VYPR

facefusion

by Facefusion

CVEs (1)

  • CVE-2026-84702HigSep 2, 2026
    risk 0.42cvss 7.5epss

    facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at…