Intel

AIKIDO-2026-260480

rumenx/php-sitemap is vulnerable to Path Traversal

Path TraversalGHSA-r934-gc26-cjrx Published 5 days ago

20

Low Risk

This Affects:

PHPrumenx/php-sitemap
0.0.1 - 1.0.3
Fixed in 1.0.4
Are you affected? Scan for Free

TL;DR

Sitemap::store() concatenates the output directory with the caller supplied $filename without removing path separators or .. segments before writing the file. Untrusted filename values can escape the intended output directory and write sitemap output to arbitrary filesystem locations writable by the PHP process. The fix rejects filenames containing NUL bytes, path separators, or ./.. and reduces the value to a basename before building the path.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you pass externally influenced input into the $filename argument of store().

Background info

rumenx/php-sitemap is vulnerable to Path Traversal in versions 0.0.1 - 1.0.3.

How to fix this

Upgrade the rumenx/php-sitemap library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform