craftcms/cms is vulnerable to Path Traversal
20
Low Risk
The path-containment check in Craft CMS's local file system validates a path before normalizing it and prepending the volume prefix. Because normalization happens after validation, the assumptions made during validation can be invalidated when resolving asset file streams, creating a theoretical path-traversal condition. No exploitable scenario was demonstrated, but the ordering of validation and normalization is unsafe. The fix reorders the steps so the final resolved path is checked for containment.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Path Traversal in versions 4.0.0 - 4.18.1 and 5.0.0 - 5.10.5.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant