THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2xmm-m4wv-3fjh (low) — October CMS: Incomplete Scheme Validation in Image Resizer

[GHSA] GHSA-2xmm-m4wv-3fjh (low) — October CMS: Incomplete Scheme Validation in Image Resizer

medgithub_advisoriesPublished 2026-09-14

GHSA-2xmm-m4wv-3fjh Severity: low CVE: None

October CMS: Incomplete Scheme Validation in Image Resizer

The image resizer classified external sources by testing whether the source string began with the substring `http`, and the string-source branch in `ResizeImageItem::fromObject()` accepted any value containing `://` as a URL. As a result, non-http(s) PHP stream wrappers such as `phar://`, `file

Original source: https://github.com/advisories/GHSA-2xmm-m4wv-3fjh