THREAT OPS › Threat News › [GHSA] GHSA-6j4c-mgqr-qv76 (medium) — Kirby: Access to image files outside of the site root via path traversal in the media handling
[GHSA] GHSA-6j4c-mgqr-qv76 (medium) — Kirby: Access to image files outside of the site root via path traversal in the media handling
GHSA-6j4c-mgqr-qv76 Severity: medium CVE: CVE-2026-75592
Kirby: Access to image files outside of the site root via path traversal in the media handling
### TL;DR
This vulnerability affects all Kirby sites that are deployed in a way that their `index` root on the server is next to a second directory that is read-accessible to PHP and shares the same name prefix (such as the site with the index r
Indicators of compromise
- CVE-2026-75592cve
Original source: https://github.com/advisories/GHSA-6j4c-mgqr-qv76