CVE-2026-23877 | swingmx swingmusic up to 2.1.3 /folder/dir-browser list_folders path traversal (GHSA-pj88-9xww-gxmh / EUVD-2026-3284)
A vulnerability marked as problematic has been reported in swingmx swingmusic up to 2.1.3. This affects the function list_folders of the file /folder/dir-browser. Performing a manipulation results in path traversal: '/../filedir'.
This vulnerability is reported as CVE-2026-23877. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.