by Leo Feyer
Path traversal in the images controller
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
Unauthenticated visitors might be able to see images outside the files directory. Files inside the files directory, especially in protected folders, are not affected.
Affected versions
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11
Suggested solution
Upgrade to Contao 5.3.50 or 5.7.12.
More information
https://github.com/contao/contao/security/advisories/GHSA-mrvp-7wmx-5m4h