LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-85684

Published
CVSS9.1
Severitycritical
WeaknessCWE-73
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-85684

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-85684.