9.1
CVE-2026-25057
- EPSS 0.47%
- Veröffentlicht 09.02.2026 19:16:55
- Zuletzt bearbeitet 19.02.2026 20:25:55
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Zip Slip in MarkUs config upload allowing RCE
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to create an assignment from an exported configuration (courses/<:course_id>/assignments/upload_config_files). The uploaded zip file entry names are used to create paths to write files to disk without checking these paths. This vulnerability is fixed in 2.9.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Markusproject ≫ Markus Version < 2.9.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.47% | 0.368 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
https://github.com/MarkUsProject/Markus/releases/tag/v2.9.1
https://github.com/MarkUsProject/Markus/security/advisories/GHSA-mccg-p332-252h
https://github.com/MarkUsProject/Markus/commit/0ca002a1f0071c7a00dbb2ed34fede57323c5dc7