Path Traversal Vulnerability in Marker by Datalab
CVE-2026-85684

8.8HIGH

Key Information:

Vendor

Datalab-to

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85684?

The Marker application, up to version 2.0.0, contains a vulnerability in its file upload handler that allows unauthenticated attackers to exploit the system. By manipulating the filename parameter, attackers can use directory traversal sequences to write or overwrite files at arbitrary locations within the filesystem. This flaw poses significant risks, including the potential for unauthorized data modification and loss of system integrity.

Affected Version(s)

marker 0 <= 2.0.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.