CRITICALVulnerability
CVE-2026-85684
marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system.
Properties
- severity
- CRITICAL
- score
- 9.1
- cve_id
- CVE-2026-85684
- signal_observed_at
- 2026-09-23T22:44:45+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- published_at
- 2026-09-04T15:17:46.077
- last_modified
- 2026-09-23T17:17:46.567
Related Entities (2)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]External Control of File Name or Path
Explore deeper with Ninja Signal's threat intelligence graph