THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9vx2-j98c-p72w (high) — Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling

[GHSA] GHSA-9vx2-j98c-p72w (high) — Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling

medgithub_advisoriesPublished 2026-08-31

GHSA-9vx2-j98c-p72w Severity: high CVE: CVE-2026-75594

Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling

### TL;DR

This vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes (`%2f`), such as nginx, PHP's built-in server or Apache setups that have the opt

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9vx2-j98c-p72w