{"id":"GHSA-52vm-mxx8-f227","summary":"Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths","details":"### Impact\n\nIn Phantom \u003c= 1.3.0, when `PHANTOM_OUTPUT_DIR` was unset (the default), the MCP tools accepted arbitrary absolute output paths with no confinement. Anything able to send tool calls (e.g. an AI agent driving the MCP interface) could **write or overwrite arbitrary files** the process user can write — including shell startup files (`~/.zshrc`) or a Reaper `__startup.lua`, which is effectively local code execution on a developer workstation.\n\nSeparately, the stem-separation and render paths decoded input audio with no size/duration cap (the analysis path was already guarded). A small, highly compressed FLAC/OGG could expand to multi-gigabyte PCM, causing memory-exhaustion DoS, and widened exposure to decoder bugs including libsndfile CVE-2026-37555.\n\n### Patches\nFixed in **1.3.1**:\n- File writes are always confined to `PHANTOM_OUTPUT_DIR` (default `~/.phantom/output`); symlinks resolved and re-verified on the final path.\n- Decode/duration/size guards mirrored onto the separation and render paths (plus ffmpeg `-max_alloc`/`-t`/`-fs`).\n- Atomic `O_CREAT|O_EXCL` output creation in reference matching and symlink-TOCTOU hardening on confined input reads.\n\n### Workarounds\nSet `PHANTOM_OUTPUT_DIR` (and optionally `PHANTOM_AUDIO_DIR`) to dedicated directories before starting the server.\n\n### Credit\nFound during an internal security audit.","modified":"2026-07-09T13:45:36.024533237Z","published":"2026-07-09T13:37:34Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-09T13:37:34Z","nvd_published_at":null,"cwe_ids":["CWE-22","CWE-400","CWE-73"]},"references":[{"type":"WEB","url":"https://github.com/fadelabs/phantom/security/advisories/GHSA-52vm-mxx8-f227"},{"type":"PACKAGE","url":"https://github.com/fadelabs/phantom"}],"affected":[{"package":{"name":"phantom-audio","ecosystem":"PyPI","purl":"pkg:pypi/phantom-audio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.1"}]}],"versions":["1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.3.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.3.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-52vm-mxx8-f227/GHSA-52vm-mxx8-f227.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}