{"id":"GHSA-7hxc-f267-h5q7","title":"Craft CMS: Incorrect path validation could potentially lead to path traversal","summary":"Craft CMS: Incorrect path validation could potentially lead to path traversal","severity":"low","cwe":["CWE-22"],"vendor":"craftcms","product":"craftcms/cms","ecosystem":"composer","affected":["craftcms/cms >= 5.0.0-RC1, < 5.10.6","craftcms/cms >= 4.0.0-RC1, < 4.18.2"],"patched":["craftcms/cms 5.10.6","craftcms/cms 4.18.2"],"published":"2026-08-06","updated":"2026-08-06","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-7hxc-f267-h5q7","references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-7hxc-f267-h5q7"},{"url":"https://github.com/craftcms/cms/commit/a8425b6c707335e42c35ee2aaf03af50ea4a494d"},{"url":"https://github.com/craftcms/cms/commit/bd6b9c175b4892e042e8a03760c39b0e94c4c7d6"},{"url":"https://github.com/craftcms/cms/releases/tag/4.18.2"},{"url":"https://github.com/craftcms/cms/releases/tag/5.10.6"},{"url":"https://github.com/advisories/GHSA-7hxc-f267-h5q7"}],"tags":["ghsa","composer"],"ingestedAt":"2026-08-06T22:05:23.121Z","slug":"GHSA-7hxc-f267-h5q7","body":"## Overview\n\nThe `ensurePathIsContained` function of the `Local` file system class is theoretically vulnerable to path traversal, although no exploitable scenario has been discovered.\n\nWhen a file is read, an `Asset` object uses the `getFileStream` method of the `Volume` where the asset file is stored, which in turn uses the `getFileStream` method of the file system class used by that `Volume`. For the `Local` file system, this function returns a stream to a file on the local disk after verifying and creating the correct file path.\n\nThe file path is constructed by first validating the path and then adding a prefix to the validated and normalized path. The prefix is the path to the local directory that houses the particular volume. The order of operations matters here: first, a validation step, afterward a normalization step, and finally the construction of the resulting file path. This opens the possibility of a desanitization-style vulnerability, where the normalization invalidates the assumptions made by the validation or sanitization that preceded it.\n\n## Impact\n\nThe issue is not directly exploitable, but for hardening, a fix is recommended regardless.\n\n## Affected packages\n\n- `craftcms/cms >= 5.0.0-RC1, < 5.10.6`\n- `craftcms/cms >= 4.0.0-RC1, < 4.18.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `craftcms/cms 5.10.6`\n- `craftcms/cms 4.18.2`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}