VYPR
Medium severity4.9NVD Advisory· Published Mar 6, 2026· Updated Jun 17, 2026

CVE-2026-27807

CVE-2026-27807

Description

MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update various entities (e.g., assignment settings). These YAML files are parsed with aliases enabled. This issue has been patched in version 2.9.4.

Affected products

3
  • MarkUsProject/Markusllm-fuzzy3 versions
    <2.9.4+ 2 more
    • (no CPE)range: <2.9.4
    • (no CPE)range: < 2.9.4
    • cpe:2.3:a:markusproject:markus:*:*:*:*:*:*:*:*range: <2.9.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.