Junglewise Threat Intelligence

CVE-2026-56394: Craft CMS path traversal in assets/icon endpoint

CVE-2026-56394 · Severity: medium · CVSS 6.5 · Published 2026-06-21

Vendors: Craft CMS.

Executive brief

Craft CMS, a popular content management system, contains a security flaw that allows logged-in users to access files they should not be able to see. By manipulating specific web requests, an attacker can bypass security checks to read internal SVG files from the server. This could lead to the exposure of sensitive system information or assets, potentially aiding further attacks.

Technical details

An authenticated path traversal vulnerability exists in Craft CMS within the `assets/icon` endpoint. The root cause is a logic error in `src/helpers/Assets.php` where file existence checks are performed on the user-supplied `extension` parameter before input validation occurs. Specifically, `Assets::iconPath()` constructs a file path using the raw input; if the file exists, it is returned and served via `sendFile()` before the `preg_match` validation in `Assets::iconSvg()` can be executed. An attacker with authenticated access can use traversal sequences (e.g., `../`) to resolve to and read arbitrary `.svg` files on the local filesystem that are accessible to the web server process. The issue is resolved in versions 4.17.7 and 5.9.13.

Affected products

  • Craft CMS CMS >= 4.0.0-RC1, < 4.17.7; >= 5.0.0-RC1, < 5.9.13

Timeline

  • 2026-06-02: advisory: GitHub Security Advisory GHSA-c43v-4cr8-6mvp published
  • 2026-06-21: disclosed: CVE-2026-56394 published to NVD

References