{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/facefusion--3.6.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:facefusion:facefusion:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-84702"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Facefusion (\u003c= 3.6.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Facefusion"],"content_html":"\u003cp\u003eFacefusion versions up to and including 3.6.1 contain a critical path traversal vulnerability within the \u003ccode\u003eget_job_file_name\u003c/code\u003e function. The application fails to properly sanitize or normalize user-supplied job identifiers provided via the HTTP API. This oversight enables an unauthenticated attacker to inject directory traversal sequences, such as dot-dot-slash patterns, into the job identifier parameter. By manipulating this input, an attacker can escape the intended storage directory and write files to arbitrary locations on the underlying host filesystem. This vulnerability presents a high risk as it facilitates remote code execution if an attacker manages to overwrite sensitive system binaries, configuration files, or startup scripts. Defenders should identify instances of Facefusion in their environment and prioritize upgrading to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-84702 allows unauthorized file creation and modification on the target server. This can lead to full system compromise, data corruption, or persistent access for an attacker, depending on the ability to overwrite critical system files or web root contents.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of Facefusion running in the environment and verify the version is above 3.6.1.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering for the Facefusion HTTP API to prevent untrusted traffic from reaching the endpoint, particularly for deployments exposed to the internet.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for requests containing directory traversal patterns (e.g., ../ or ..) within job-related API endpoints.\u003c/li\u003e\n\u003cli\u003ePatch Facefusion immediately upon the release of a version addressing CVE-2026-84702.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T03:10:57Z","date_published":"2026-09-02T03:10:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-facefusion-path-traversal/","summary":"An unauthenticated path traversal vulnerability in Facefusion versions 3.6.1 and earlier allows remote attackers to perform arbitrary file writes via malicious job identifiers.","title":"CVE-2026-84702 Path Traversal in Facefusion","url":"https://feed.craftedsignal.io/briefs/2026-09-facefusion-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Facefusion (\u003c= 3.6.1)","version":"https://jsonfeed.org/version/1.1"}