Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fastapiadmin:fastapi-admin:2.1:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.2.0:*:*:*:*:*:*:* |
cpe:2.3:a:fastapiadmin:fastapiadmin:*:*:*:*:*:*:*:* |
| Vendors & Products |
Fastapiadmin fastapi-admin
|
Wed, 25 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastapiadmin fastapi-admin
|
|
| CPEs | cpe:2.3:a:fastapiadmin:fastapi-admin:2.0:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.1:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fastapiadmin fastapi-admin
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastapiadmin
Fastapiadmin fastapiadmin |
|
| Vendors & Products |
Fastapiadmin
Fastapiadmin fastapiadmin |
Mon, 23 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Scheduled Task API. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Title | FastApiAdmin Scheduled Task API controller.py upload_controller unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-23T13:18:42.686Z
Reserved: 2026-02-22T15:09:07.919Z
Link: CVE-2026-2977
Updated: 2026-02-23T13:18:36.321Z
Status : Analyzed
Published: 2026-02-23T08:16:13.757
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-2977
No data.
OpenCVE Enrichment
Updated: 2026-04-18T18:00:06Z