
CVE-2024-43035 Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer endpoint. This occurs in serveFiles… https://www.cve.org/CVERecord?id=CVE-2024-43035
Post summary
The CVE-2024-43035 entry documents a directory‑traversal flaw in Fonoster’s VoiceServer endpoints that could allow attackers to read arbitrary files, but no exploit proof‑of‑concept, active exploitation, or patch details are provided.

