{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/surya/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:surya:surya:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85687"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["surya (0.22.1)"],"_cs_severities":["high"],"_cs_tags":["webserver","vulnerability","file-read","cve-2026-85687"],"_cs_type":"advisory","_cs_vendors":["surya"],"content_html":"\u003cp\u003eThe surya screenshot server version 0.22.1 contains a high-severity arbitrary file read vulnerability (CVE-2026-85687). The issue exists within the /info, /page, and /process routes, which accept user-supplied raw file_path parameters without proper validation or sanitization. By supplying arbitrary file paths to these endpoints, an unauthenticated attacker can leverage the application's underlying Image.open or pypdfium2.PdfDocument processing logic to read and exfiltrate image or PDF files from the underlying filesystem. Additionally, the /info route can be utilized as an existence oracle to confirm the presence of sensitive files on the host, facilitating reconnaissance prior to exfiltration. This vulnerability exposes files accessible by the user context running the surya server process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to read arbitrary files from the server's filesystem, including sensitive images or PDF documents. This can result in the exposure of confidential information, intellectual property, or system configurations, potentially leading to a broader compromise of the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading the surya screenshot server to a version that addresses CVE-2026-85687.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the surya server endpoints (/info, /page, /process) to trusted internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eConduct log reviews for anomalous requests containing directory traversal sequences or references to unexpected system file paths targeting the affected routes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-04T15:31:40Z","date_published":"2026-09-04T15:31:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85687-surya/","summary":"The surya screenshot server version 0.22.1 is vulnerable to an unauthenticated arbitrary file read vulnerability via the /info, /page, and /process routes, allowing attackers to access sensitive local files.","title":"Unauthenticated Arbitrary File Read in surya Screenshot Server","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85687-surya/"}],"language":"en","title":"CraftedSignal Threat Feed - Surya","version":"https://jsonfeed.org/version/1.1"}