Path traversal in Kirby - #VU138447
Published: July 20, 2026
Kirby
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the media handler when processing requests for ungenerated media thumbnails. A remote attacker can send a specially crafted request to disclose sensitive information.
Exploitation is possible only when the site index root is adjacent to a PHP-readable sibling directory sharing the same name prefix, and the targeted media file has a prepared thumbnail job file.