CVE-2026-100909 | OctoberCMS up to 4.1.19/4.2.25/4.3.4 ResizeImages.php getSourcePathForResize realSourcePath server-side request forgery (GHSA-2xmm-m4wv-3fjh)

SecurityVulns

A vulnerability labeled as critical has been found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery.

This vulnerability was named CVE-2026-100909. The attack may be performed from remote. In addition, an exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More