The project is actively maintained, organization-backed, well documented, and supported by testing and security tooling. Workflow auditing also found high-confidence template-injection and secret-inheritance issues, so this preview needs careful isolation and review.
68%
Total Score
100
86
100
The artifact contains license files, but the manifest declares the package proprietary while detected license text is MIT-0. That mismatch creates a real legal and transparency concern despite the presence of licensing material.
This release is an alpha preview while the package has an established stable major and only 5% recent prereleases. The release notes explicitly say not to use Kirby 6 in production yet.
All four workflows were analyzed and use pinned actions, with no untrusted checkout or script-injection trigger detected. However, high-confidence template-injection findings and secrets-inherit findings remain, while the floating latest container image adds workflow hygiene risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-75592 getkirby/cms is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 4.9.5 and 5.0.0 - 5.5.2. | 0.0.0 - 4.9.55.0.0 - 5.5.2 | Medium |
CVE-2026-71415 getkirby/cms is vulnerable to Missing Authorization in versions 5.0.0 - 5.5.2. | 5.0.0 - 5.5.2 | High |
CVE-2026-75594 getkirby/cms is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 4.9.4 and 5.0.0 - 5.5.2. | 0.0.0 - 4.9.45.0.0 - 5.5.2 | High |
CVE-2026-69127 getkirby/cms is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 0.0.0 - 4.9.4 and 5.0.0 - 5.5.2. | 0.0.0 - 4.9.45.0.0 - 5.5.2 | Medium |
CVE-2026-54005 getkirby/cms is vulnerable to Missing Authorization in versions 0.0.0 - 4.9.3 and 5.0.0-alpha.1 - 5.4.3. | 0.0.0 - 4.9.35.0.0-alpha.1 - 5.4.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version 2.18.4 | — | — |
symfony/yaml Version 7.4.14 | — | — |
composer/semver Version 3.4.4 | — | — |
erusev/parsedown Version 1.8.0 | — | — |
phpmailer/phpmailer Version 7.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.