Path traversal in Flarum - CVE-2026-41887

 

Path traversal in Flarum - CVE-2026-41887

Published: April 20, 2026


Vulnerability identifier: #VU126537
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41887
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to path traversal in the LESS parser when compiling LESS config variables from theme color settings. A remote privileged user can submit a specially crafted setting value to disclose sensitive information.

The contents of an imported resource are embedded into the compiled forum.css, which is publicly served.


Affected software

Flarum

How to mitigate CVE-2026-41887

Install security update from vendor's website.

Flarum - addressed in versions 1.8.16, 2.0.0 rc.1

External References

Related Security Bulletins