PT-2026-84581 · Unknown · Facefusion

·

CVE-2026-84702

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions facefusion versions prior to 3.6.2
Description The software fails to normalize job identifiers within the get job file name() function. This allows unauthenticated attackers to use traversal sequences in the job identifier parameter via the HTTP API to write files to arbitrary locations outside the intended jobs directory.
Recommendations Update facefusion to version 3.6.2 or later. As a temporary mitigation, restrict access to the HTTP API to prevent unauthenticated users from supplying malicious job identifiers.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84702

Affected Products

Facefusion