THREAT OPS › Threat News › [GHSA] GHSA-rf2p-vh74-7vvh (medium) — Kirby: System path exposure from error messages in the REST API
[GHSA] GHSA-rf2p-vh74-7vvh (medium) — Kirby: System path exposure from error messages in the REST API
GHSA-rf2p-vh74-7vvh Severity: medium CVE: CVE-2026-69127
Kirby: System path exposure from error messages in the REST API
### TL;DR
This vulnerability affects all Kirby sites that have not disabled the REST API with the `'api' => false` option.
It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-69127cve
Original source: https://github.com/advisories/GHSA-rf2p-vh74-7vvh