Filesystem Containment Vulnerability in Kirby CMS by GetKirby
CVE-2026-75592
6.9MEDIUM
What is CVE-2026-75592?
Kirby, an open-source content management system, is susceptible to a filesystem containment vulnerability due to inadequate checks in its media handler. This flaw allows a remote attacker to exploit the method Kirby\Cms\Media::thumb(), enabling them to create and access thumbnails from image files located in sibling directories outside of the intended root path. If these directories contain a valid .json thumbnail job file, it may expose sensitive internal data, such as staging sites or backups, risking the integrity and confidentiality of the information. The issue is resolved in Kirby versions 4.9.5 and 5.5.2.
Affected Version(s)
kirby < 4.9.5 < 4.9.5
kirby >= 5.0.0, < 5.5.2 < 5.0.0, 5.5.2
