Junglewise Threat Intelligence

CVE-2026-51027: Andreas Haugstrup Pedersen FileThingie path traversal in ft2.php

CVE-2026-51027 · Severity: critical · CVSS 9.9 · Published 2026-07-20

Executive brief

FileThingie, a web-based file management tool, contains a security flaw that allows users to move files outside of their permitted folders. By manipulating the web address during a file move operation, an attacker with basic login access can bypass security restrictions to write or move files into sensitive system directories. This could lead to a complete takeover of the web server or the deletion of critical system files.

Technical details

A path traversal vulnerability exists in FileThingie v.2.5.7 due to flawed logic in the 'move' action within ft2.php. The application attempts to prevent directory traversal by comparing the number of '../' sequences in the destination path against the number of '/' characters in the current directory path. An attacker can bypass this check using 'slash inflation'—submitting a directory parameter containing a large number of redundant forward slashes (e.g., '////'). Because the underlying OS and PHP libraries normalize multiple slashes into a single separator, the attacker can satisfy the count-based validation while traversing to arbitrary locations on the file system. This allows an authenticated attacker to move or write files to sensitive directories outside the application root.

Affected products

  • Andreas Haugstrup Pedersen (leefish) FileThingie 2.5.7

Timeline

  • 2026-07-20: disclosed: CVE-2026-51027 published

References

Related threats