CRITICAL 9.1 CVE-2026-85684 Published 4 Sept 2026

FastAPI Path Traversal Vulnerability

Worried this affects one of your servers?

FastAPI, a modern web framework, is affected by a path traversal vulnerability in the marker application through version 2.0.0.

An unauthenticated attacker can exploit this issue by supplying specially crafted filenames containing directory traversal sequences, allowing them to write arbitrary files to any location or delete existing files on the system.

Reference: CVE-2026-85684 on NVD

← Back to Security News