Threat Advisory

Kirby Flaw Lets Attackers Access Image and JSON Files via Path Traversal

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in getkirby/cms, affecting versions not explicitly stated in this article. The overall risk and impact are significant, as attackers can exploit these vulnerabilities to gain unauthorized access to sensitive data.

CVE-2026-75594 (CVSS 7.5 — High): An attacker can access image files and limited access to JSON files outside of the site root via path traversal in the media handling of Kirby.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in getkirby/cms, affecting versions not explicitly stated in this article. The overall risk and impact are significant, as attackers can exploit these vulnerabilities to gain unauthorized access to sensitive data.

CVE-2026-75594 (CVSS 7.5 — High): An attacker can access image files and limited access to JSON files outside of the site root via path traversal in the media handling of Kirby.[emaillocker id="1283"]

CVE-2026-71415: File upload permissions are not checked during processing of chunk data, allowing an attacker to potentially exploit this vulnerability.

These vulnerabilities collectively present a significant risk to administrators who have not applied patches.

RECOMMENDATION:

We recommend you to update getkirby/cms to version 5.5.2

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu