Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 19 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:markusproject:markus:*:*:*:*:*:*:*:* |
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Markusproject
Markusproject markus |
|
| Vendors & Products |
Markusproject
Markusproject markus |
Mon, 09 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to create an assignment from an exported configuration (courses/<:course_id>/assignments/upload_config_files). The uploaded zip file entry names are used to create paths to write files to disk without checking these paths. This vulnerability is fixed in 2.9.1. | |
| Title | Zip Slip in MarkUs config upload allowing RCE | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-10T16:00:52.427Z
Reserved: 2026-01-28T14:50:47.889Z
Link: CVE-2026-25057
Updated: 2026-02-10T15:32:12.424Z
Status : Analyzed
Published: 2026-02-09T20:15:56.550
Modified: 2026-02-19T20:25:55.387
Link: CVE-2026-25057
No data.
OpenCVE Enrichment
Updated: 2026-04-17T21:30:28Z