Path Traversal Vulnerability in Kirby Content Management System
CVE-2026-75594

8.2HIGH

Key Information:

Vendor

Getkirby

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-75594?

An issue in Kirby, an open-source content management system, has been identified where its media handler improperly validates filenames, allowing attackers to exploit this vulnerability. Prior versions 4.9.5 and 5.5.2 are susceptible to remote attacks where encoded slash characters could be used to navigate outside designated media directories. Successful exploitation can lead to the disclosure of arbitrary JSON files and other media asset files, presenting significant risks to the integrity and confidentiality of stored data. This vulnerability has been mitigated in the latest releases, emphasizing the importance of upgrading to protect against such attacks.

Affected Version(s)

kirby < 4.9.5 < 4.9.5

kirby >= 5.0.0, < 5.5.2 < 5.0.0, 5.5.2

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.