GHSA-67cx-w7gv-x726HighCVSS 7.5
facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing...
🔗 CVE IDs covered (1)
📋 Description
facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-84702
- https://github.com/facefusion/facefusion/commit/a2cbfd73b10191e51ed2eb1e83c19121153e0a22
- https://github.com/facefusion/facefusion
- https://github.com/facefusion/facefusion/blob/3.6.1/facefusion/jobs/job_manager.py
- https://github.com/facefusion/facefusion/releases/tag/3.7.0
- https://github.com/geo-chen/oss/blob/main/facefusion.md
- https://www.vulncheck.com/advisories/facefusion-before-3.7.0-path-traversal-via-job-identifier
- https://github.com/advisories/GHSA-67cx-w7gv-x726