von Leo Feyer

Path-Traversal im Jobs-Modul

Datum: 15.06.2026
CVE-ID: CVE-2026-55825

Beschreibung

Es ist theoretisch möglich, über eine manipulierte Download-URL die Log-Datei eines anderen Jobs herunterzuladen.

Betroffene Versionen

Contao 5.7 bis 5.7.6

Empfohlene Lösung

Update auf Contao 5.7.7.

Workaround

-

Mehr Informationen

https://github.com/contao/contao/security/advisories/GHSA-grm4-wm43-9jh5