🚨 CVE-2026-84702
facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.
🎖@cveNotify

GitHub
GitHub - facefusion/facefusion: Industry leading face manipulation platform
Industry leading face manipulation platform. Contribute to facefusion/facefusion development by creating an account on GitHub.
September 2, 2026 40