External Control of File Name or Path in Kirby - #VU150667

 

External Control of File Name or Path in Kirby - #VU150667

Published: September 17, 2026


Vulnerability identifier: #VU150667
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to write content to arbitrary locations on the server.

The vulnerability exists due to external control of file name or path in Kirby page creation functionality when processing unfiltered root or dirname parameters. A remote user can submit a page creation request with crafted path parameters to write content to arbitrary locations on the server.

The Panel\'s page creation dialog is not an entry point.


Affected software

Kirby

Remediation

Install security update from vendor's website.

Kirby - addressed in versions 4.9.6, 5.6.0

External References

Related Security Bulletins