von Leo Feyer
Path-Traversal im Jobs-Modul
Datum: 15.06.2026
CVE-ID: CVE-2026-55825
Beschreibung
Es ist theoretisch möglich, über eine manipulierte Download-URL die Log-Datei eines anderen Jobs herunterzuladen.
Betroffene Versionen
Contao 5.7 bis 5.7.6
Empfohlene Lösung
Update auf Contao 5.7.7.
Workaround
-
Mehr Informationen
https://github.com/contao/contao/security/advisories/GHSA-grm4-wm43-9jh5