PatchSiren

facefusion CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH facefusion CVE published 2026-09-02

CVE-2026-84702

CVE-2026-84702 is a high-severity vulnerability in facefusion, a software that allows attackers to write files outside the jobs directory by supplying traversal sequences in the job identifier parameter through the unauthenticated HTTP API. This vulnerability has significant implications for defenders, who must assess exposure and prioritize patching or mitigations to prevent potential file writes. The vu [truncated]