Medium severity4.9NVD Advisory· Published Mar 6, 2026· Updated Jun 17, 2026
CVE-2026-27807
CVE-2026-27807
Description
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update various entities (e.g., assignment settings). These YAML files are parsed with aliases enabled. This issue has been patched in version 2.9.4.
Affected products
3<2.9.4+ 2 more
- (no CPE)range: <2.9.4
- (no CPE)range: < 2.9.4
- cpe:2.3:a:markusproject:markus:*:*:*:*:*:*:*:*range: <2.9.4
Patches
Vulnerability mechanics
References
2- github.com/MarkUsProject/Markus/security/advisories/GHSA-m9rx-85mx-q9h6nvdVendor Advisory
- github.com/MarkUsProject/Markus/releases/tag/v2.9.4nvdProductRelease Notes
News mentions
0No linked articles in our index yet.