{"id":"CVE-2026-84702","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-84702","summary":"facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences…","details":"facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.","published":"2026-09-02T01:17:25.430","modified":"2026-09-02T01:17:25.430","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/facefusion/facefusion/commit/a2cbfd73b10191e51ed2eb1e83c19121153e0a22","label":"facefusion/facefusion@a2cbfd7"},"references":[{"type":"WEB","url":"https://github.com/facefusion/facefusion"},{"type":"WEB","url":"https://github.com/facefusion/facefusion/blob/3.6.1/facefusion/jobs/job_manager.py"},{"type":"WEB","url":"https://github.com/facefusion/facefusion/commit/a2cbfd73b10191e51ed2eb1e83c19121153e0a22"},{"type":"WEB","url":"https://github.com/facefusion/facefusion/releases/tag/3.7.0"},{"type":"WEB","url":"https://github.com/geo-chen/oss/blob/main/facefusion.md"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/facefusion-before-3.7.0-path-traversal-via-job-identifier"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-02T01:17:25.430"}}