Path Traversal Vulnerability in Kirby Content Management System
CVE-2026-75594
8.2HIGH
What is CVE-2026-75594?
An issue in Kirby, an open-source content management system, has been identified where its media handler improperly validates filenames, allowing attackers to exploit this vulnerability. Prior versions 4.9.5 and 5.5.2 are susceptible to remote attacks where encoded slash characters could be used to navigate outside designated media directories. Successful exploitation can lead to the disclosure of arbitrary JSON files and other media asset files, presenting significant risks to the integrity and confidentiality of stored data. This vulnerability has been mitigated in the latest releases, emphasizing the importance of upgrading to protect against such attacks.
Affected Version(s)
kirby < 4.9.5 < 4.9.5
kirby >= 5.0.0, < 5.5.2 < 5.0.0, 5.5.2
