Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mrvp-7wmx-5m4h | Contao: Path traversal in the images controller |
Fri, 09 Oct 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contao
Contao contao |
|
| Vendors & Products |
Contao
Contao contao |
Fri, 09 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12. | |
| Title | Contao: Path traversal in the images controller | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T19:24:02.625Z
Reserved: 2026-10-08T22:34:49.291Z
Link: CVE-2026-107844
No data.
Status : Received
Published: 2026-10-09T20:17:10.313
Modified: 2026-10-09T20:17:10.313
Link: CVE-2026-107844
No data.
OpenCVE Enrichment
Updated: 2026-10-09T20:30:11Z
Github GHSA