๐Ÿ” CVE Alert

CVE-2026-25962

MEDIUM 6.5

MarkUs: Zip bomb in config upload enables DoS

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs currently extracts zip files without any size or entry-count limits. For example, instructors can upload a zip file to provide an assignment configuration; students can upload a zip file for an assignment submission and indicate its contents should be extracted. This issue has been patched in version 2.9.4.

CWE CWE-409
Vendor markusproject
Product markus
Published Mar 6, 2026
Last Updated Mar 6, 2026
Stay Ahead of the Next One

Get instant alerts for markusproject markus

Be the first to know when new medium vulnerabilities affecting markusproject markus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

MarkUsProject / Markus
< 2.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MarkUsProject/Markus/security/advisories/GHSA-x8xv-j7fc-65x5 github.com: https://github.com/MarkUsProject/Markus/releases/tag/v2.9.4