THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rf2p-vh74-7vvh (medium) — Kirby: System path exposure from error messages in the REST API

[GHSA] GHSA-rf2p-vh74-7vvh (medium) — Kirby: System path exposure from error messages in the REST API

medgithub_advisoriesPublished 2026-09-01

GHSA-rf2p-vh74-7vvh Severity: medium CVE: CVE-2026-69127

Kirby: System path exposure from error messages in the REST API

### TL;DR

This vulnerability affects all Kirby sites that have not disabled the REST API with the `'api' => false` option.

It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rf2p-vh74-7vvh