Executive brief
HTMLy is an open-source content management system (CMS). A security flaw in the system's autosave feature allows a logged-in user with low privileges to move or rename important system files. This could lead to website downtime, loss of configuration data, or the corruption of site content by moving critical files into a draft folder where they no longer function correctly.
Technical details
A path traversal vulnerability exists in HTMLy CMS through version 3.1.1 within the autosave functionality. The /admin/autosave endpoint accepts a user-controlled 'oldfile' parameter which is passed directly to PHP's file_exists() and rename() functions in admin.php without proper canonicalization or directory boundary enforcement. An authenticated attacker with low privileges (such as an Author) can use directory traversal sequences (../) to reference and relocate any file writable by the web server process to a draft location. This can result in the corruption of application configuration, denial of service, or unauthorized modification of content owned by other users. Mitigation involves using realpath() to canonicalize paths and verifying that the resolved path resides within the intended content directory.
Affected products
- danpros HTMLy through 3.1.1
Timeline
- 2026-06-25: disclosed: Vulnerability reported by Midhun Mohanan
- 2026-06-25: advisory