THREAT OPS › Threat News › [GHSA] GHSA-9vx2-j98c-p72w (high) — Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
[GHSA] GHSA-9vx2-j98c-p72w (high) — Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
GHSA-9vx2-j98c-p72w Severity: high CVE: CVE-2026-75594
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
### TL;DR
This vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes (`%2f`), such as nginx, PHP's built-in server or Apache setups that have the opt
Indicators of compromise
- CVE-2026-75594cve
Original source: https://github.com/advisories/GHSA-9vx2-j98c-p72w