Junglewise Threat Intelligence

CVE-2026-25869: MiniGal Nano path traversal in index.php via dir parameter

CVE-2026-25869 · Severity: high · CVSS 7.5 · Published 2026-02-11

Executive brief

MiniGal Nano is a lightweight PHP-based image gallery used to display photos on websites. A security flaw allows an attacker to bypass folder restrictions and view files outside of the intended photo directory. This could lead to the exposure of sensitive system information or private files stored on the web server.

Technical details

A path traversal vulnerability exists in MiniGal Nano versions 0.3.5 and prior within the 'dir' parameter of index.php. The application attempts to sanitize user input by removing '..' sequences before appending the input to the photos directory path; however, this filter can be bypassed using crafted directory patterns. An unauthenticated remote attacker can exploit this to enumerate and display image files from any directory readable by the web server process. This vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory).

Affected products

  • MiniGal MiniGal Nano 0.3.5 and prior

Timeline

  • 2026-02-11: advisory: Initial advisory published by VulnCheck
  • 2026-02-11: disclosed: CVE-2026-25869 assigned

References

Related threats