Skip to content

MCPA-2026-0042

highpath-traversalCVSS 7.7

Phantom arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

Phantom (PyPI: phantom-audio) through 1.3.0: when PHANTOM_OUTPUT_DIR is unset (the default), the MCP tools accept arbitrary absolute output paths with no confinement — anything able to send tool calls (e.g. a prompt-injected agent) can write or overwrite arbitrary files the process user can write, including shell startup files, plus a decode-bomb denial of service. Fixed in 1.3.1.

Affected packages

EcosystemPackageAffected versions
pypiphantom-audio
>= 0, < 1.3.1

Identifiers

GHSA-52vm-mxx8-f227CWE-22CWE-73CWE-400

References

Timeline

  • Published: 2026-07-09

← All advisories