CVE-2026-85687 PUBLISHED

surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server

Assigner: VulnCheck
Reserved: 04.09.2026 Published: 04.09.2026 Updated: 04.09.2026

surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can read any image or PDF file on the host by supplying arbitrary file paths to Image.open or pypdfium2.PdfDocument, obtaining rendered contents as base64 and using /info as an existence oracle.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor datalab-to
Product surya
Versions Default: unaffected
  • affected from 0 to 0.22.1 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • External Control of File Name or Path CWE