CVE-2026-84702

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 01:17

Updated : 2026-09-02 14:17


NVD link : CVE-2026-84702

Mitre link : CVE-2026-84702

CVE.ORG link : CVE-2026-84702


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')