GHSA-67cx-w7gv-x726HighCVSS 7.5

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing...

Published
September 2, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.

🔗 References (8)