Path Traversal Vulnerability in Craft CMS by Pixel & Tonic
CVE-2026-72783
What is CVE-2026-72783?
Craft CMS versions ranging from 5.0.0-RC1 to below 5.10.6, as well as from 4.0.0-RC1 to below 4.18.2, exhibit a potential path traversal vulnerability due to the implementation of the 'ensurePathIsContained' function in the Local file system class. The vulnerability arises when the order of operations processes path validation prior to normalization, leading to a scenario where malicious actors could potentially access files outside the intended directory structure. Although the vendor has indicated that the vulnerability is not directly exploitable and no attacks have been discovered to take advantage of it, applying the recommended fixes is crucial to enhance system integrity and harden security.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.6
cms 4.0.0-RC1 < 4.18.2
cms 5.10.6
