Executive brief
Craft CMS, a popular content management system, contains a security flaw that allows logged-in users to access files they should not be able to see. By manipulating specific web requests, an attacker can bypass security checks to read internal SVG files from the server. This could lead to the exposure of sensitive system information or assets, potentially aiding further attacks.
Technical details
An authenticated path traversal vulnerability exists in Craft CMS within the `assets/icon` endpoint. The root cause is a logic error in `src/helpers/Assets.php` where file existence checks are performed on the user-supplied `extension` parameter before input validation occurs. Specifically, `Assets::iconPath()` constructs a file path using the raw input; if the file exists, it is returned and served via `sendFile()` before the `preg_match` validation in `Assets::iconSvg()` can be executed. An attacker with authenticated access can use traversal sequences (e.g., `../`) to resolve to and read arbitrary `.svg` files on the local filesystem that are accessible to the web server process. The issue is resolved in versions 4.17.7 and 5.9.13.
Affected products
- Craft CMS CMS >= 4.0.0-RC1, < 4.17.7; >= 5.0.0-RC1, < 5.9.13
Timeline
- 2026-06-02: advisory: GitHub Security Advisory GHSA-c43v-4cr8-6mvp published
- 2026-06-21: disclosed: CVE-2026-56394 published to NVD