Path traversal in Kirby - CVE-2026-75592
Published: July 20, 2026 / Updated: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the media handler when processing requests for ungenerated media thumbnails. A remote attacker can send a specially crafted request to disclose sensitive information.
Exploitation is possible only when the site index root is adjacent to a PHP-readable sibling directory sharing the same name prefix, and the targeted media file has a prepared thumbnail job file.