CVE-2026-27807

MEDIUM

MarkUs <2.9.4 - Deserialization

Title source: llm
STIX 2.1

Description

MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update various entities (e.g., assignment settings). These YAML files are parsed with aliases enabled. This issue has been patched in version 2.9.4.

Scores

CVSS v3 4.9
EPSS 0.0007
EPSS Percentile 20.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-776
Status published
Products (1)
markusproject/markus < 2.9.4
Published Mar 06, 2026
Tracked Since Mar 06, 2026