CVE-2026-84702 | facefusion up to 3.6.x Job File Name Normalization get_job_file_name job_identifier path traversal

SecurityVulns

A vulnerability described as problematic has been identified in facefusion up to 3.6.x. Affected is the function get_job_file_name of the component Job File Name Normalization. Executing a manipulation of the argument job_identifier can lead to path traversal.

This vulnerability is registered as CVE-2026-84702. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More