CVE-2026-85687
surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can read any image or PDF file on the host by supplying arbitrary file paths to Image.open or pypdfium2.PdfDocument, obtaining rendered contents as base64 and using /info as an existence oracle.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.29%
- CWE
- CWE-73
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- datalab-to surya
Weakness type
Related vulnerabilities
- CVE-2026-53956 — Rattler vulnerable to package cache path traversal via conda package build string
- CVE-2026-86751 — Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown
- CVE-2026-86741 — Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA
- CVE-2026-79692 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87815 — SiYuan before v3.8.2 Path Traversal via removeRiffDeck
- CVE-2026-53581 — ntp: write path traversal
- CVE-2026-86995 — n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
- CVE-2026-78620 — Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling