THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7hxc-f267-h5q7 (low) — Craft CMS: Incorrect path validation could potentially lead to path traversal

[GHSA] GHSA-7hxc-f267-h5q7 (low) — Craft CMS: Incorrect path validation could potentially lead to path traversal

medgithub_advisoriesPublished 2026-08-06

GHSA-7hxc-f267-h5q7 Severity: low CVE: None

Craft CMS: Incorrect path validation could potentially lead to path traversal

The `ensurePathIsContained` function of the `Local` file system class is theoretically vulnerable to path traversal, although no exploitable scenario has been discovered.

When a file is read, an `Asset` object uses the `getFileStream` method of the `Volume` where the asset f

Original source: https://github.com/advisories/GHSA-7hxc-f267-h5q7