CRITICAL🇵🇱 Wersja polska

CVE-2026-30121

CVSS 9.1pub. 2026-06-15upd. 2026-06-16

remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-123 (Write-what-where Condition) consists of insufficient path or input data validation during file write operations. An attacker can supply crafted input data, resulting in content being written to a path controlled by the attacker in the file system. This operation is possible remotely, without authentication and without user interaction.

Impact

An attacker can overwrite critical system or application files, which may lead to system integrity violation, malicious code execution (e.g., by injecting startup scripts or configurations), or permanent application damage (denial of service).

Mitigation & patch

Patches available from the vendor should be applied according to the references. It is recommended to monitor the project repository at the address indicated in the references and update to a patched version immediately after its release.

Who is affected

remotion-dev remotion version v4.0.409

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References