Executive brief
marker is a PDF-to-markdown conversion tool with an optional FastAPI server component. The /marker/upload endpoint fails to validate uploaded filenames, allowing attackers to write arbitrary files to any location on the system or delete existing files by supplying specially-crafted directory traversal sequences (e.g., "../../../etc/passwd"). This affects systems running the optional server component.
Technical details
marker through version 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler due to insufficient sanitization of the file.filename parameter. The vulnerability exists in marker/scripts/server.py where uploaded files are written using unsanitized user-supplied filenames containing directory traversal sequences (../, etc.). No authentication is required—the endpoint is publicly accessible. An unauthenticated attacker can exploit this to write files to arbitrary filesystem locations (including application directories, configuration folders, or system paths) or overwrite/delete existing files, leading to arbitrary code execution, privilege escalation, or denial of service. Patches should sanitize filenames by stripping or rejecting directory traversal components; fixed versions and detailed remediation guidance are available from the vendor.
Affected products
- datalab-to marker through 2.0.0
Timeline
- 2026-09-04: disclosed