Low · 3.7 PHP packages GHSA-mrvp-7wmx-5m4h CVE-2026-107844 PKSA-6j5h-bxmj-94h9
Contao path-traversal in ImagesController (CVE-2026-107844)
Contao's ImagesController can be abused via a user-controlled path parameter to return files from the project tree when names match allowed image extensions. Vendor updates fix the issue.
AI summary
A path traversal vulnerability (CVE-2026-107844 / GHSA-mrvp-7wmx-5m4h) affects contao/core-bundle image handling. An unauthenticated request can cause the ImagesController to return files outside the intended image directory when certain path parameters include encoded parent-directory segments. The issue is fixed in vendor updates.
What happened
ImagesController concatenates a user-controlled {path} parameter to the configured image target directory with Path::join() but does not verify the canonical path with Path::isBasePath(). As a result, an unauthenticated request including encoded parent-directory segments can cause BinaryFileResponse to return files under the project directory when those files' names use an extension allowed by contao.image.valid_extensions. The route can also be used to probe whether arbitrary paths exist; debug responses may disclose absolute filesystem paths. Paths below the upload directory were not shown to be readable in the published reports.
Technical cause
The controller uses Path::join() to construct a file path from a user-supplied {path} but does not call Path::isBasePath() to confirm the canonicalized path remains inside the configured image directory. That missing base-path check allows encoded parent-directory segments to escape the intended directory.
Why it matters
An attacker can make unauthenticated requests that return files from the project directory when filenames match the configured allowed image extensions, exposing file contents. The route can also be used to determine whether specific paths exist, and debug-mode responses can reveal absolute filesystem paths, increasing information exposure risk.
Who is affected
The vulnerability affects contao/core-bundle releases in the ranges reported by advisories: versions from 4.1.0 up to (but not including) 5.3.50, and versions beginning at 5.4.0-RC1 up to (but not including) 5.7.12. The advisories also note impact starting at 5.0.0 through 5.3.50 in some descriptions — consult the exact installed release against the vendor advisory.
Discovery and timeline
Public advisories and database entries for this issue were published on 2026-10-09. The advisory records include publication timestamps: 2026-10-09T20:53:55+02:00 (advisory entries) and an NVD record with 2026-10-09T20:17:10+02:00.
Affected and fixed versions
Reported fixed releases for contao/core-bundle are 5.3.50 and 5.7.12. Affected ranges reported across sources include: >= 4.1.0, < 5.3.50 and >= 5.4.0-RC1, < 5.7.12. Some descriptions also call out 5.0.0 through 5.3.50 as impacted. Verify your installed version against those ranges.
Fixes and mitigation
A vendor fix is available. The vulnerability is listed as fixed in contao/core-bundle 5.3.50 and 5.7.12 according to the advisory records.
Recommended action
If you run contao/core-bundle in any of the affected ranges, apply the vendor update to a fixed release (5.3.50 or 5.7.12 as appropriate). Confirm the installed package version before updating and validate the patch after deployment.
PatchBriefing score
3.7 / 10 · Low
Official CVSS: 5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Why this score
CVSS v3.1 base score: 5.3 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The advisory's Patchwire score is 3.7. Contributing factors reported in the advisory data include that the flaw is remotely reachable without authentication and requires no user interaction; public exploit and known-exploited signals were not reported in the sources.
Affected versions
- contao/core-bundle ≥ 5.4.0-RC1 < 5.7.12
- vulnerable
- contao/core-bundle
- vulnerable
- contao/core-bundle >=5.4.0-RC1,<5.7.12|>=4.1.0,<5.3.50
- vulnerable
- contao/core-bundle >= 5.4.0-RC1, < 5.7.12
- vulnerable
- ≥ 5.3.50
- patched
- ≥ 5.7.12
- patched
Reported fixes
A vendor fix is available. The vulnerability is listed as fixed in contao/core-bundle 5.3.50 and 5.7.12 according to the advisory records.
How this was built
4 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
Packagist Security Advisories registry
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email