CVE-2026-2977 PUBLISHED

FastApiAdmin Scheduled Task API controller.py upload_controller unrestricted upload

Assigner: VulDB
Reserved: 22.02.2026 Published: 23.02.2026 Updated: 23.02.2026

A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Scheduled Task API. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor n/a
Product FastApiAdmin
Versions
  • Version 2.0 is affected
  • Version 2.1 is affected
  • Version 2.2.0 is affected

References

Problem Types

  • Unrestricted Upload CWE
  • Improper Access Controls CWE