Path Traversal Vulnerability in Contao CMS by Contao
CVE-2026-107844
What is CVE-2026-107844?
A path traversal vulnerability exists in Contao CMS versions up to 5.3.50 and 5.7.12. The issue arises from the ImagesController's handling of the user-controlled {path} parameter, which is concatenated with the configured image target directory without sufficient validation. An attacker can manipulate the {path} parameter through encoded parent-directory segments, potentially revealing sensitive files within the project directory. This security flaw could also expose whether arbitrary filesystem paths exist and might inadvertently leak absolute filesystem paths through debug responses. Although this vulnerability does not allow access to paths located below the upload directory, it still poses a significant risk if left unaddressed. This issue is resolved in the latest releases: versions 5.3.50 and 5.7.12.
Affected Version(s)
contao >= 5.0.0, < 5.3.50 < 5.0.0, 5.3.50
contao >= 5.4.0-RC1, < 5.7.12 < 5.4.0-RC1, 5.7.12
