CVE-2026-107844 | Contao up to 5.3.49/5.7.11 Image ImagesController Path::join path path traversal

SecurityVulns

A vulnerability was found in Contao up to 5.3.49/5.7.11. It has been declared as problematic. This issue affects the function Path::join of the file ImagesController of the component Image Handler. Executing a manipulation of the argument path can lead to path traversal.

This vulnerability is tracked as CVE-2026-107844. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More