CVE-2026-75592 | getkirby Kirby up to 4.9.4/5.5.1 Media src/Filesystem/Dir.php realpath path traversal

SecurityVulns

A vulnerability, which was classified as critical, has been found in getkirby Kirby up to 4.9.4/5.5.1. This impacts the function KirbyFilesystemDir::realpath/KirbyFilesystemF::realpath of the file src/Filesystem/Dir.php of the component Media Handler. Performing a manipulation results in path traversal.

This vulnerability is identified as CVE-2026-75592. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More