Unauthenticated Arbitrary File Read in Surya Screenshot Server by Datalab
CVE-2026-85687

8.7HIGH

Key Information:

Vendor

Datalab-to

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85687?

The Surya 0.22.1 screenshot server is vulnerable to an unauthenticated arbitrary file read flaw, which allows attackers to exploit the /info, /page, and /process endpoints. By supplying crafted file_path parameters, malicious users can access any accessible image or PDF file on the server. This vulnerability facilitates the retrieval of sensitive information by allowing attackers to use /info as an existence oracle, decoding returned content into base64 format. It poses a serious risk to the confidentiality and integrity of data on the affected system.

Affected Version(s)

surya 0 <= 0.22.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.