Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Datalab-to
Datalab-to surya |
|
| Vendors & Products |
Datalab-to
Datalab-to surya |
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can read any image or PDF file on the host by supplying arbitrary file paths to Image.open or pypdfium2.PdfDocument, obtaining rendered contents as base64 and using /info as an existence oracle. | |
| Title | surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T17:45:02.009Z
Reserved: 2026-09-04T13:51:43.257Z
Link: CVE-2026-85687
No data.
Status : Received
Published: 2026-09-04T15:17:46.507
Modified: 2026-09-04T15:17:46.507
Link: CVE-2026-85687
No data.
OpenCVE Enrichment
Updated: 2026-09-04T16:00:05Z
-
CWE-73
External Control of File Name or Path