CVE-2026-84702
facefusion before 3.7.0 Path Traversal via Job Identifier
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.
| CWE | CWE-22 |
| Vendor | facefusion |
| Product | facefusion |
| Published | Sep 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for facefusion facefusion
Be the first to know when new high vulnerabilities affecting facefusion facefusion are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
facefusion / facefusion
0 < 3.7.0
References
github.com: https://github.com/facefusion/facefusion github.com: https://github.com/geo-chen/oss/blob/main/facefusion.md github.com: https://github.com/facefusion/facefusion/blob/3.6.1/facefusion/jobs/job_manager.py github.com: https://github.com/facefusion/facefusion/commit/a2cbfd73b10191e51ed2eb1e83c19121153e0a22 github.com: https://github.com/facefusion/facefusion/releases/tag/3.7.0 vulncheck.com: https://www.vulncheck.com/advisories/facefusion-before-3.7.0-path-traversal-via-job-identifier
Credits
George Chen