{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avikunjamarker/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vikunja:marker:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-85684"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["marker (\u003c= 2.0.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Vikunja"],"content_html":"\u003cp\u003eThe marker library, through version 2.0.0, contains a critical path traversal vulnerability within its FastAPI-based /marker/upload handler. The vulnerability stems from the application's failure to properly sanitize the file.filename parameter before using it in file system operations.\u003c/p\u003e\n\u003cp\u003eThis security flaw allows unauthenticated, remote attackers to traverse directories by providing malicious filenames containing sequences like \u0026quot;../\u0026quot; or \u0026quot;..\\\u0026quot;. Depending on the application's permissions, an attacker can overwrite critical system files to achieve Remote Code Execution (RCE) or delete existing files to cause a Denial of Service (DoS). This vulnerability is particularly dangerous in high-privilege environments where the web application service account has write access to system-critical directories. Organizations using software that incorporates the marker library are advised to verify their dependencies and ensure they are not exposing the vulnerable upload endpoint to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-85684 results in unauthorized file system access. This can lead to full system compromise through the overwriting of binaries, configuration files, or startup scripts, or lead to catastrophic data loss and service interruption via the deletion of necessary application or system components. Given the CVSS 3.1 base score of 9.1, this represents a significant risk to the integrity and availability of any environment running the affected software version.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate any application using the marker library to a version beyond 2.0.0, or apply the specific security patches provided by the package maintainers when available.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the file.filename parameter to detect and reject directory traversal sequences (e.g., \u0026quot;../\u0026quot;, \u0026quot;..\\\u0026quot;) before the data is processed by the /marker/upload handler.\u003c/li\u003e\n\u003cli\u003eRun the application service with the principle of least privilege, ensuring the service account lacks write access to sensitive system directories.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to monitor and block POST requests to /marker/upload that contain directory traversal patterns in the filename metadata.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:26:31Z","date_published":"2026-09-04T15:26:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-marker-path-traversal/","summary":"An unauthenticated path traversal vulnerability in the marker library up to version 2.0.0 allows attackers to overwrite or delete arbitrary files on the system by manipulating the file.filename parameter.","title":"Path Traversal Vulnerability in Marker Upload Handler (CVE-2026-85684)","url":"https://feed.craftedsignal.io/briefs/2026-09-marker-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vikunja:marker:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}