Exposure of Sensitive System Information to an Unauthorized Control Sphere in Kirby - #VU138445
Published: July 20, 2026
Kirby
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive system information.
The vulnerability exists due to exposure of sensitive system information in the REST API error handler when handling crafted API requests that trigger internal errors. A remote attacker can send a specially crafted request to disclose sensitive system information.
The issue can expose the full filesystem path of the installation, and unauthenticated API access is sufficient when the REST API is enabled.