PT-2026-30677 · Pypi+1 · Requests+1
Programsurf
+2
·
Published
2026-04-06
·
Updated
2026-04-27
·
CVE-2026-34981
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
whisperX versions 0.3.1 through 0.5.0
Description
The whisperX API, a tool for enhancing and analyzing audio content, has a flaw in the
FileService.download from url() function within app/services/file service.py. This function uses requests.get(url) without proper URL validation. The file extension check is performed after the HTTP request, allowing bypass by appending '.mp3' to internal URLs. The /speech-to-text-url endpoint is accessible without authentication.Recommendations
Update to version 0.6.0 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Requests
Whisperx