PT-2026-84581 · Unknown · Facefusion
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
facefusion versions prior to 3.6.2
Description
The software fails to normalize job identifiers within the
get job file name() function. This allows unauthenticated attackers to use traversal sequences in the job identifier parameter via the HTTP API to write files to arbitrary locations outside the intended jobs directory.Recommendations
Update facefusion to version 3.6.2 or later.
As a temporary mitigation, restrict access to the HTTP API to prevent unauthenticated users from supplying malicious job identifiers.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Facefusion