THREAT OPS › Threat News › [GHSA] GHSA-grm4-wm43-9jh5 (low) — Contao: Possible path traversal in job download URIs
[GHSA] GHSA-grm4-wm43-9jh5 (low) — Contao: Possible path traversal in job download URIs
GHSA-grm4-wm43-9jh5 Severity: low CVE: CVE-2026-55825
Contao: Possible path traversal in job download URIs
## Summary
An authenticated backend user who can access one job can request an attachment identifier containing `../` segments and make the job attachment download endpoint read a file from another job directory inside `var/job-attachments`.
The controller authorizes only the `jobUuid` ro
Indicators of compromise
- CVE-2026-55825cve
Original source: https://github.com/advisories/GHSA-grm4-wm43-9jh5