by Leo Feyer

Path traversal in the jobs module

Date: 2026-06-15
CVE ID: CVE-2026-55825

Description

It is theoretically possible to download the log file of another job by using a manipulated download URL.

Affected versions

Contao 5.7 up to 5.7.6

Suggested solution

Upgrade to Contao 5.7.7.

Workaround

-

More information

https://github.com/contao/contao/security/advisories/GHSA-grm4-wm43-9jh5