Executive brief
Typemill, a lightweight content management system, contains a security flaw that allows users with 'Author' permissions to access files they should not be able to see. By manipulating web requests, an authorized user can read sensitive system files located outside of the standard content folders. This could lead to the exposure of configuration data or other private information, potentially compromising the entire website.
Technical details
A path traversal vulnerability exists in Typemill's file handling logic prior to version 2.24.0. The flaw is located in the Storage::getFile() method, where an attacker can provide directory traversal sequences (e.g., ../) via the 'path' query parameter. When an empty folder argument is supplied, the traversal-prevention controls in Storage::getFolderPath() can be bypassed. This allows an authenticated user with at least Author-level privileges to read arbitrary files on the server's filesystem that the web server process has permission to access. The issue was addressed in version 2.24.0 and subsequent releases.
Affected products
- Typemill Typemill before 2.24.0
Timeline
- 2026-06-14: patched: Version 2.24.0 released with security fixes.
- 2026-06-17: disclosed: CVE-2026-49133 published.