---
id: GHSA-7hxc-f267-h5q7
title: 'Craft CMS: Incorrect path validation could potentially lead to path traversal'
summary: 'Craft CMS: Incorrect path validation could potentially lead to path traversal'
severity: low
cwe:
  - CWE-22
vendor: craftcms
product: craftcms/cms
ecosystem: composer
affected:
  - 'craftcms/cms >= 5.0.0-RC1, < 5.10.6'
  - 'craftcms/cms >= 4.0.0-RC1, < 4.18.2'
patched:
  - craftcms/cms 5.10.6
  - craftcms/cms 4.18.2
published: '2026-08-06'
updated: '2026-08-06'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-7hxc-f267-h5q7'
references:
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-7hxc-f267-h5q7'
  - url: >-
      https://github.com/craftcms/cms/commit/a8425b6c707335e42c35ee2aaf03af50ea4a494d
  - url: >-
      https://github.com/craftcms/cms/commit/bd6b9c175b4892e042e8a03760c39b0e94c4c7d6
  - url: 'https://github.com/craftcms/cms/releases/tag/4.18.2'
  - url: 'https://github.com/craftcms/cms/releases/tag/5.10.6'
  - url: 'https://github.com/advisories/GHSA-7hxc-f267-h5q7'
tags:
  - ghsa
  - composer
ingestedAt: '2026-08-06T22:05:23.121Z'
---

## Overview

The `ensurePathIsContained` function of the `Local` file system class is theoretically vulnerable to path traversal, although no exploitable scenario has been discovered.

When a file is read, an `Asset` object uses the `getFileStream` method of the `Volume` where the asset file is stored, which in turn uses the `getFileStream` method of the file system class used by that `Volume`. For the `Local` file system, this function returns a stream to a file on the local disk after verifying and creating the correct file path.

The file path is constructed by first validating the path and then adding a prefix to the validated and normalized path. The prefix is the path to the local directory that houses the particular volume. The order of operations matters here: first, a validation step, afterward a normalization step, and finally the construction of the resulting file path. This opens the possibility of a desanitization-style vulnerability, where the normalization invalidates the assumptions made by the validation or sanitization that preceded it.

## Impact

The issue is not directly exploitable, but for hardening, a fix is recommended regardless.

## Affected packages

- `craftcms/cms >= 5.0.0-RC1, < 5.10.6`
- `craftcms/cms >= 4.0.0-RC1, < 4.18.2`

## Remediation

Upgrade to a patched release:

- `craftcms/cms 5.10.6`
- `craftcms/cms 4.18.2`
