CVE-2026-25962
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs curren
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs currently extracts zip files without any size or entry-count limits. For example, instructors can upload a zip file to provide an assignment configuration.
students can upload a zip file for an assignment submission and indicate its contents should be extracted. This issue has been patched in version 2.9.4.
MEDIUM · CVSS 6.5
EPSS 0.00062
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0