---
id: CVE-2026-107844
title: Contao is an Open Source CMS
summary: >-
  Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12,
  ImagesController joins the user-controlled {path} parameter to the configured
  image target directory with Path::join() but does not use Path::isBasePath()
  to verif…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-22
vendor: contao
product: contao/core-bundle
affected:
  - 'contao/core-bundle >= 4.1.0, < 5.3.50'
  - 'contao/core-bundle >= 5.4.0-RC1, < 5.7.12'
patched:
  - contao/core-bundle 5.3.50
  - contao/core-bundle 5.7.12
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:17:10.313'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107844'
references:
  - url: >-
      https://github.com/contao/contao/commit/867c055122fdf12220f973f862082037b695b9bd
    label: security-advisories@github.com
  - url: 'https://github.com/contao/contao/releases/tag/5.3.50'
    label: security-advisories@github.com
  - url: 'https://github.com/contao/contao/releases/tag/5.7.12'
    label: security-advisories@github.com
  - url: 'https://github.com/contao/contao/security/advisories/GHSA-mrvp-7wmx-5m4h'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-mrvp-7wmx-5m4h'
tags:
  - nvd
  - ghsa
  - composer
aliases:
  - GHSA-mrvp-7wmx-5m4h
ecosystem: composer
ingestedAt: '2026-10-09T21:12:42.318Z'
---

## Overview

Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107844)

Affected packages:

- `contao/core-bundle >= 4.1.0, < 5.3.50`
- `contao/core-bundle >= 5.4.0-RC1, < 5.7.12`

Patched in:

- `contao/core-bundle 5.3.50`
- `contao/core-bundle 5.7.12`

Source: https://github.com/advisories/GHSA-mrvp-7wmx-5m4h
