Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fastapiadmin:fastapi-admin:2.1:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.2.0:*:*:*:*:*:*:* |
cpe:2.3:a:fastapiadmin:fastapiadmin:*:*:*:*:*:*:*:* |
| Vendors & Products |
Fastapiadmin fastapi-admin
|
Wed, 25 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastapiadmin fastapi-admin
|
|
| CPEs | cpe:2.3:a:fastapiadmin:fastapi-admin:2.0:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.1:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fastapiadmin fastapi-admin
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastapiadmin
Fastapiadmin fastapiadmin |
|
| Vendors & Products |
Fastapiadmin
Fastapiadmin fastapiadmin |
Mon, 23 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/module_system/user/controller.py of the component Scheduled Task API. Executing a manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used. | |
| Title | FastApiAdmin Scheduled Task API controller.py user_avatar_upload_controller unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-23T13:07:05.795Z
Reserved: 2026-02-22T15:09:13.479Z
Link: CVE-2026-2979
Updated: 2026-02-23T13:06:58.636Z
Status : Analyzed
Published: 2026-02-23T09:17:01.427
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-2979
No data.
OpenCVE Enrichment
Updated: 2026-04-18T11:15:35Z