Description
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Authenticated Path Traversal
Action: Immediate Patch
AI Analysis

Impact

Formwork before version 2.3.13 contains a path traversal flaw in the BackupController that allows authenticated panel users with backup download or delete permission to read or delete arbitrary files outside the backup directory. The attacker can supply a base64‑encoded backslash‑separated traversal payload that bypasses PHP's basename on Linux, enabling access to files that should remain protected. The primary impact of this vulnerability is the possible compromise of confidentiality and integrity of system files due to unauthorized file disclosure or deletion, as identified by CWE-22.

Affected Systems

The vulnerability affects installations of Formwork prior to version 2.3.13. All users running any older version of the getformwork:formwork product are potentially vulnerable. Only newer releases that include the fix are safe.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. Exploitation requires user authentication and specific backup permissions, so it is not an unauthenticated remote code execution but still significant due to the ability to read or delete arbitrary files. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers who obtain backup download or delete rights can craft a payload that bypasses normal file restrictions, making the risk notable for systems where backup permissions are widely granted.

Generated by OpenCVE AI on October 3, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Formwork to version 2.3.13 or later which contains the path‑traversal fix.
  • Restrict backup download and delete permissions to trusted users until the upgrade can be performed.
  • Audit backup permissions and monitor logs for suspicious download or delete activity.

Generated by OpenCVE AI on October 3, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
Description Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
Title Formwork before 2.3.13 Path Traversal via BackupController Download and Delete
First Time appeared Formwork Project
Formwork Project formwork
Weaknesses CWE-22
CPEs cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:*
Vendors & Products Formwork Project
Formwork Project formwork
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Formwork Project Formwork
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T23:28:48.001Z

Reserved: 2026-10-02T00:55:58.388Z

Link: CVE-2026-104478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-03T00:16:36.083

Modified: 2026-10-03T00:16:36.220

Link: CVE-2026-104478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T00:30:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')