Description
Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12.
Published: 2026-10-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated File Read via Path Traversal
Action: Apply Patch
AI Analysis

Impact

Contao’s ImagesController combines a user‑supplied {path} parameter with the configured image directory using Path::join() but fails to confirm that the resulting canonical path still resides within that directory. As a result, an attacker can supply encoded parent‑directory segments to read any file whose name ends with an extension allowed by contao.image.valid_extensions. The returned file is provided via BinaryFileResponse, enabling the disclosure of project‑level files to unauthenticated users. The route can also be used to determine whether arbitrary paths exist, and when debug responses are enabled, absolute filesystem paths may be exposed. Overall, the vulnerability enables information disclosure rather than code execution.

Affected Systems

All installations of contao:contao from version 5.0.0 up to the release of 5.3.50 and up to 5.7.12 are vulnerable. Versions 5.3.50, 5.7.12 and newer contain the fix and are therefore not affected.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, and the EPSS score is not available, suggesting that no current exploitation data is reported. The vulnerability is listed as not being in the CISA KEV catalog. An attacker can trigger it by sending an unauthenticated HTTP request to the images controller, incorporating parent‑directory encodings to traverse directories, and supplying a valid file extension. The attack is straightforward for an attacker with network access to the web server; no prior authentication, privilege escalation, or code execution is required. The primary risk is the accidental or intentional disclosure of configuration, application source, or other sensitive files included in the Contao project directory.

Generated by OpenCVE AI on October 9, 2026 at 20:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Contao to version 5.3.50 or later, or to 5.7.12 or later, which removes the path traversal flaw.
  • If an immediate upgrade is not possible, restrict access to the images controller route to authenticated users or remove the route entirely from public request handling.
  • Restrict the list of allowed image extensions (contao.image.valid_extensions) to the minimal set required for normal operation, and disable debug mode so that absolute paths are no longer revealed.

Generated by OpenCVE AI on October 9, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
Vendors & Products Contao
Contao contao

Fri, 09 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12.
Title Contao: Path traversal in the images controller
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T19:24:02.625Z

Reserved: 2026-10-08T22:34:49.291Z

Link: CVE-2026-107844

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T20:17:10.313

Modified: 2026-10-09T20:17:10.313

Link: CVE-2026-107844

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T20:30:11Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')