THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6j4c-mgqr-qv76 (medium) — Kirby: Access to image files outside of the site root via path traversal in the media handling

[GHSA] GHSA-6j4c-mgqr-qv76 (medium) — Kirby: Access to image files outside of the site root via path traversal in the media handling

medgithub_advisoriesPublished 2026-09-02

GHSA-6j4c-mgqr-qv76 Severity: medium CVE: CVE-2026-75592

Kirby: Access to image files outside of the site root via path traversal in the media handling

### TL;DR

This vulnerability affects all Kirby sites that are deployed in a way that their `index` root on the server is next to a second directory that is read-accessible to PHP and shares the same name prefix (such as the site with the index r

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6j4c-mgqr-qv76