VDB
CVE-2026-53449
CVE-2026-53449
PUBLISHED
CVSS 6 MEDIUM
Reported by GitHub_M · Published July 10, 2026
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access can overwrite arbitrary files writable by the coturn process because the command string is used as-is after stripping the psd prefix and leading spaces, allowing truncation and overwrite with session dump data. This issue is fixed in version 4.13.0.
Risk Scores
CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| coturn | coturn | < 4.13.0 |
| coturn | coturn | < 4.13.0, < 4.13.0 |
Timeline
- Jul 10, 2026 CVE Published
- Jul 11, 2026 EPSS Score
- Jul 11, 2026 Coalition ESS Score
- Jul 13, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 Security Advisory
- Sep 2, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
References
- https://github.com/coturn/coturn/security/advisories/GHSA-jj76-vwjw-w34r x_refsource_CONFIRM
- https://github.com/coturn/coturn/commit/e72930f571beba3bc7a9f97661af2614aae92a55 x_refsource_MISC
- https://github.com/coturn/coturn/releases/tag/4.13.0 x_refsource_MISC