CVE-2026-27897Disclosure(wanderingastronomer / vociferous)

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch wanderingastronomer vociferous systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dialog to handle the file path, the API does not validate the filename string before it is processed by the backends filesystem logic. Because the API is unauthenticated and the CORS configuration in app.py is overly permissive (allow_origins=["*"] or allowing localhost), an external attacker can bypass the UI entirely. By using directory traversal sequences (../), an attacker can force the app to write arbitrary data to any location accessible by the current user's permissions. This vulnerability is fixed in 4.4.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vociferous

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-11); latest day: 2
  • 6 total mentions across 2 days

Affected systems

Products
vociferous

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-03-11: 4Mentions · 2026-03-15: 2PoC Mentioned / Linked · 2026-03-11: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-15: 1Technical Details · 2026-03-11: 403-1103-15
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
PoC
116.7%
General
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-114
Disclosure2Patch1PoC1
2026-03-152
General1Patch1
Full discourse6 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-27897 Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_f… https://www.cve.org/CVERecord?id=CVE-2026-27897 ----- Traducción: CVE-2026-27897 Voc… http://infoflow.cloud`

    Post summary

    A brief mention of CVE-2026-27897 with a link to the CVE record; no additional details or actionable information is provided.

    0000039
    57 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27897 Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_f… https://www.cve.org/CVERecord?id=CVE-2026-27897

    Post summary

    CVE-2026-27897 is a vulnerability in Vociferous present before release 4.4.2 and is fixed in that version.

    00000213
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27897 Path Traversal in Vociferous Speech-to-Text Application B... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27897 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A newly identified CVE‑2026‑27897 is disclosed as a Path Traversal flaw in a speech‑to‑text application, with a link to details but no PoC, exploit, or patch information provided.

    0000023
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27897: CRITICAL] Vociferous app pre-4.4.2 version had a vulnerability in the export_file route allowing unrestricted file writing. Update to 4.4.2 for security.#cve,CVE-2026-27897,#cybersecurity https://cvefind.com/CVE-2026-27897

    Post summary

    The advisory reports a critical unrestricted file‑write vulnerability in pre‑4.4.2 versions of the Vociferous app and urges users to upgrade to version 4.4.2 to mitigate the risk.

    0000033
    602 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27897 - Critical Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The applic... https://www.thehackerwire.com/vulnerability/CVE-2026-27897/ https://t.co/0b4ceGbfRG

    Post summary

    The tweet announces CVE‑2026‑27897, a critical vulnerability in Vociferous’ export_file route that existed before version 4.4.2. No proof‑of‑concept, exploit, patch, or evidence of active exploitation is provided.

    0000022
    134 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-27897: Vociferou... CORS wildcard + unauthenticated path traversal = instant RCE via malicious webpage writing shells anywhere on disk. #CSRF #PathTraversal #RCE. https://zerodaysignal.com/vulnerability/CVE-2026-27897 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑27897, providing technical details of the RCE mechanism and a link to a possible PoC, but does not mention active exploitation, patches, or false positives.

    0000058
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwanderingastronomervociferous---

Explore more