<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:facefusion:facefusion:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afacefusionfacefusion/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 03:10:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afacefusionfacefusion/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-84702 Path Traversal in Facefusion</title><link>https://feed.craftedsignal.io/briefs/2026-09-facefusion-path-traversal/</link><pubDate>Wed, 02 Sep 2026 03:10:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-facefusion-path-traversal/</guid><description>An unauthenticated path traversal vulnerability in Facefusion versions 3.6.1 and earlier allows remote attackers to perform arbitrary file writes via malicious job identifiers.</description><content:encoded><![CDATA[<p>Facefusion versions up to and including 3.6.1 contain a critical path traversal vulnerability within the <code>get_job_file_name</code> function. The application fails to properly sanitize or normalize user-supplied job identifiers provided via the HTTP API. This oversight enables an unauthenticated attacker to inject directory traversal sequences, such as dot-dot-slash patterns, into the job identifier parameter. By manipulating this input, an attacker can escape the intended storage directory and write files to arbitrary locations on the underlying host filesystem. This vulnerability presents a high risk as it facilitates remote code execution if an attacker manages to overwrite sensitive system binaries, configuration files, or startup scripts. Defenders should identify instances of Facefusion in their environment and prioritize upgrading to a patched version once available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-84702 allows unauthorized file creation and modification on the target server. This can lead to full system compromise, data corruption, or persistent access for an attacker, depending on the ability to overwrite critical system files or web root contents.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of Facefusion running in the environment and verify the version is above 3.6.1.</li>
<li>Implement strict ingress filtering for the Facefusion HTTP API to prevent untrusted traffic from reaching the endpoint, particularly for deployments exposed to the internet.</li>
<li>Monitor web server access logs for requests containing directory traversal patterns (e.g., ../ or ..) within job-related API endpoints.</li>
<li>Patch Facefusion immediately upon the release of a version addressing CVE-2026-84702.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>