Executive brief
Craft CMS, a popular website content management system, contains a theoretical path traversal vulnerability in its file system handling. An attacker could potentially access files outside the intended directory. The vendor acknowledges no working exploit has been found, and the issue is a hardening recommendation rather than an active threat.
Technical details
The ensurePathIsContained function of the Local file system class validates and normalizes file paths in the wrong order: validation occurs before normalization, allowing normalization to invalidate prior validation assumptions in a desanitization-style vulnerability. When a file is read via the getFileStream method, the path is validated, normalized, and then prefixed with the volume directory. An attacker could potentially craft a path that passes validation but resolves to a location outside the intended volume directory after normalization. The vulnerability requires local file system access and has not been demonstrated as exploitable in practice. Patches are available: 5.10.6 and 4.18.2.
Affected products
- Craft CMS >= 5.0.0-RC1, < 5.10.6 and >= 4.0.0-RC1, < 4.18.2
Timeline
- 2026-07-25: disclosed
- 2026-08-11: advisory
- 2026-08-11: patched: Versions 5.10.6 and 4.18.2 released