Path traversal in Janus WebRTC Server - #VU151866

 

Path traversal in Janus WebRTC Server - #VU151866

Published: September 23, 2026


Vulnerability identifier: #VU151866
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to create or truncate files writable by Janus, including files in protected folders.

The vulnerability exists due to improper path restriction in AudioBridge recording file handling when processing record_file and record_dir values from plugin signalling API requests. A remote attacker can supply recording paths to create or truncate files writable by Janus.

Written data is limited to a fixed 44-byte RIFF header.


Affected software

Janus WebRTC Server

Remediation

Install security update from vendor's website.

Janus WebRTC Server - addressed in versions 0.16.2, 1.4.2

External References

Related Security Bulletins