VDB

CVE-2026-53449

CVE-2026-53449 PUBLISHED CVSS 6 MEDIUM

Reported by GitHub_M · Published July 10, 2026

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access can overwrite arbitrary files writable by the coturn process because the command string is used as-is after stripping the psd prefix and leading spaces, allowing truncation and overwrite with session dump data. This issue is fixed in version 4.13.0.

Risk Scores

CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersions
coturncoturn< 4.13.0
coturncoturn< 4.13.0, < 4.13.0

Timeline

  • Jul 10, 2026 CVE Published
  • Jul 11, 2026 EPSS Score
  • Jul 11, 2026 Coalition ESS Score
  • Jul 13, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 Security Advisory
  • Sep 2, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›