CVE-2026-84702

Source
https://cve.org/CVERecord?id=CVE-2026-84702
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84702.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84702
Published
2026-09-02T00:37:56.393Z
Modified
2026-09-04T03:31:01.303871094Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
facefusion before 3.7.0 Path Traversal via Job Identifier
Details

facefusion through 3.6.1 fails to normalize job identifiers in getjobfile_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84702.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/facefusion/facefusion

Affected ranges

Type
GIT
Repo
https://github.com/facefusion/facefusion
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.7.0"
        }
    ]
}

Affected versions

3.*
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2
3.2.0
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84702.json"