CVE-2026-84702 facefusion through 3.6.1 fails to normalize job… — CVE Notify — TG.ME

🚨 CVE-2026-84702
facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.

🎖@cveNotify
GitHub
GitHub - facefusion/facefusion: Industry leading face manipulation platform
Industry leading face manipulation platform. Contribute to facefusion/facefusion development by creating an account on GitHub.
September 2, 2026 39