GHSA-6j4c-mgqr-qv76
Kirby: Access to image files outside of the site root via path traversal in the media handling
Quick fix
GHSA-6j4c-mgqr-qv76 — getkirby/cms: upgrade to the fixed version with the command below.
composer require getkirby/cms:^4.9.5Details
### TL;DR
This vulnerability affects all Kirby sites that are deployed in a way that their `index` root on the server is next to a second directory that is read-accessible to PHP and shares the same name prefix (such as the site with the index root `/var/www/site` being next to `/var/www/site2`).
It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites.
----
### Introduction
A path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as `../`, an attacker can escape that directory and reach files elsewhere on the server.
### Affected components
Kirby's media handler processes requests for files in the `media` directory that have not been generated yet. It parses the provided path and finds the correct file or asset to generate a thumbnail of. Each thumbnail needs to have a prepared job file (a metadata file with file extension `.json`) in order to allow the media handler to generate a thumbnail.
The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the `media` and `index` roots of the site.
### Impact
In affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory `site2` passed the containment check of directory `site`. This allowed attackers to access media files with prepared job files that are stored within such sibling directories of the site's `index` root, opening the potential for information leaks from sensitive files stored within them, and deleting the job file in the process.
### Patches
The problem has been patched in [Kirby 4.9.5](https://github.com/getkirby/kirby/releases/tag/4.9.5) and [Kirby 5.5.2](https://github.com/getkirby/kirby/releases/tag/5.5.2). Please update to one of these or a [later version](https://github.com/getkirby/kirby/releases) to fix the vulnerability.
In all of the mentioned releases, we have hardened the containment helpers `Kirby\Filesystem\Dir::realpath()` and `Kirby\Filesystem\F::realpath()` to require either an exact match or a `DIRECTORY_SEPARATOR` boundary, so that a sibling path sharing the same name prefix can no longer pass the check. This prevents access to files outside the `index` root of the active site. We have also hardened the `Asset` class to block paths that contain the `../` sequence.
### Credits
Thanks to @0x1saac for responsibly reporting the identified issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/getkirby/kirby/security/advisories/GHSA-6j4c-mgqr-qv76[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-75592[ADVISORY]
- https://github.com/getkirby/kirby/commit/2b6fab950bc89d505ea89576bf71c8de614cc3b2[WEB]
- https://github.com/getkirby/kirby/commit/e0dca5f709adc21b36f5549df2c0619bc59da56c[WEB]
- https://github.com/getkirby/kirby[PACKAGE]
- https://github.com/getkirby/kirby/releases/tag/4.9.5[WEB]
- https://github.com/getkirby/kirby/releases/tag/5.5.2[WEB]