MCPA-2026-0042
highpath-traversalCVSS 7.7
Phantom arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
Phantom (PyPI: phantom-audio) through 1.3.0: when PHANTOM_OUTPUT_DIR is unset (the default), the MCP tools accept arbitrary absolute output paths with no confinement — anything able to send tool calls (e.g. a prompt-injected agent) can write or overwrite arbitrary files the process user can write, including shell startup files, plus a decode-bomb denial of service. Fixed in 1.3.1.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | phantom-audio | >= 0, < 1.3.1 |
Identifiers
GHSA-52vm-mxx8-f227CWE-22CWE-73CWE-400
References
- advisory https://github.com/fadelabs/phantom/security/advisories/GHSA-52vm-mxx8-f227
- web https://github.com/advisories/GHSA-52vm-mxx8-f227
Timeline
- Published: 2026-07-09