Relative Path Traversal in Kirby - CVE-2025-30159

 

Relative Path Traversal in Kirby - CVE-2025-30159

Published: April 23, 2026


Vulnerability identifier: #VU127191
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30159
CWE-ID: CWE-23
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access arbitrary files and execute unintended PHP code.

The vulnerability exists due to relative path traversal in the snippet() helper and $kirby->snippet() method when processing a dynamic snippet name during file system lookup. A remote attacker can supply a specially crafted snippet name containing traversal sequences to access arbitrary files and execute unintended PHP code.

Only sites that use dynamic snippet names based on request or user data are vulnerable; sites that use only fixed snippet names are not affected.


Affected software

Kirby

How to mitigate CVE-2025-30159

Install security update from vendor's website.

Kirby - addressed in versions 3.9.8.3, 3.10.1.2, 4.7.1

External References

Related Security Bulletins