Path traversal in Craft CMS - #VU139968

 

Path traversal in Craft CMS - #VU139968

Published: July 29, 2026


Vulnerability identifier: #VU139968
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to access files outside the intended directory.

The vulnerability exists due to path traversal in the ensurePathIsContained function of the Local file system class when constructing and normalizing file paths for file reads. A local user can supply a crafted path to access files outside the intended directory.

No exploitable scenario has been discovered, and the issue is described as theoretical.


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - addressed in versions 4.18.2, 5.10.6

External References

Related Security Bulletins