Path traversal in Kirby - #VU150668
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to write account files to arbitrary writable directories.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Kirby user creation when creating a user with a crafted ID. A remote privileged user can supply a crafted user ID to write account files outside the accounts directory.
The written filenames are index.php and .htpasswd.