by Leo Feyer

Path traversal in the images controller

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

Unauthenticated visitors might be able to see images outside the files directory. Files inside the files directory, especially in protected folders, are not affected.

Affected versions

Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11

Suggested solution

Upgrade to Contao 5.3.50 or 5.7.12.

More information

https://github.com/contao/contao/security/advisories/GHSA-mrvp-7wmx-5m4h