Impact
facefusion versions prior to 3.7.0 process job identifiers without proper normalization in the job_manager module. This oversight allows an attacker to embed path traversal sequences in the job identifier supplied via the public HTTP API. The vulnerability enables writing arbitrary files outside the intended jobs directory, potentially overwriting system or application files. The direct result is information disclosure, tampering, or remote code execution if executable files can be placed in a location that the system executes.
Affected Systems
The affected product is the facefusion application from the facefusion vendor. Versions up to and including 3.6.1 are impacted. A patch is available in version 3.7.0 and later, which normalizes job identifiers and removes the traversal path vulnerability.
Risk and Exploitability
With a CVSS score of 8.7 the technical severity is high. The vulnerability is exploitable via the unauthenticated API, meaning no prior authentication is required to supply malicious job identifiers. The EPSS score is not available, but the vulnerability being public and having a straightforward exploitation path suggests a significant exploitation likelihood. It is not listed in the CISA KEV catalog, yet the combination of high severity and open access makes it a critical risk for exposed installations.
OpenCVE Enrichment