VYPR
Unrated severityNVD Advisory· Published Feb 9, 2026· Updated Feb 10, 2026

Zip Slip in MarkUs config upload allowing RCE

CVE-2026-25057

Description

MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to create an assignment from an exported configuration (courses/<:course_id>/assignments/upload_config_files). The uploaded zip file entry names are used to create paths to write files to disk without checking these paths. This vulnerability is fixed in 2.9.1.

Affected products

2
  • MarkUs/MarkUsllm-fuzzy
    Range: <2.9.1
  • MarkUsProject/Markusv5
    Range: < 2.9.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.