Filesystem Containment Vulnerability in Kirby CMS by GetKirby
CVE-2026-75592

6.9MEDIUM

Key Information:

Vendor

Getkirby

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-75592?

Kirby, an open-source content management system, is susceptible to a filesystem containment vulnerability due to inadequate checks in its media handler. This flaw allows a remote attacker to exploit the method Kirby\Cms\Media::thumb(), enabling them to create and access thumbnails from image files located in sibling directories outside of the intended root path. If these directories contain a valid .json thumbnail job file, it may expose sensitive internal data, such as staging sites or backups, risking the integrity and confidentiality of the information. The issue is resolved in Kirby versions 4.9.5 and 5.5.2.

Affected Version(s)

kirby < 4.9.5 < 4.9.5

kirby >= 5.0.0, < 5.5.2 < 5.0.0, 5.5.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.