CVE-2026-107844: Path Traversal Vulnerability in Contao ImagesController
Vulnerability ID: CVE-2026-107844
CVSS Score: 5.3
Published: 2026-10-09
A path traversal vulnerability (CWE-22) in Contao CMS allows unauthenticated remote attackers to bypass directory boundary restrictions in ImagesController and access files within the project directory.
TL;DR
Unauthenticated path traversal in Contao ImagesController permits arbitrary reading of localized files matching allowed extensions and system directory probing.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)
- CVSS v3.1 Score: 5.3 (Medium)
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Vector: Network (Unauthenticated HTTP/HTTPS GET requests)
- EPSS Score: 0.00312 (22.18th percentile)
- Impact: Partial Information Disclosure / Local File Enumeration
- Exploit Status: Proof of Concept / Public Commit Diffs Available
- CISA KEV Status: Not Listed
Affected Systems
- Contao CMS 5.0.0 through 5.3.49
- Contao CMS 5.4.0-RC1 through 5.7.11
-
Contao CMS: >= 5.0.0, < 5.3.50 (Fixed in:
5.3.50) -
Contao CMS: >= 5.4.0-RC1, < 5.7.12 (Fixed in:
5.7.12)
Code Analysis
Commit: 867c055
Fix path traversal vulnerability in ImagesController by checking Path::isBasePath()
Exploit Details
- GitHub Security Advisory: Advisory details and test suite PoC demonstrating path traversal via ImagesController.
Mitigation Strategies
- Upgrade Contao CMS dependencies to fixed maintenance releases 5.3.50 or 5.7.12.
- Enforce Web Application Firewall (WAF) filtering on HTTP request URI parameters for path traversal sequences.
- Restrict 'contao.image.valid_extensions' configuration to essential image asset types only.
- Disable application debug mode in production deployment environments to avoid absolute path disclosure.
Remediation Steps:
- Run 'composer update contao/contao --with-dependencies' in project root environments.
- Verify that contao package versions resolved match >= 5.3.50 or >= 5.7.12.
- Clear Symfony application caches using 'php vendor/bin/contao-console cache:clear'.
- Execute automated or unit tests against ImagesController routes to confirm traversal attempts return HTTP 404.
References
- Contao Security Advisory GHSA-mrvp-7wmx-5m4h
- Contao Security Fix Commit 867c055122fdf12220f973f862082037b695b9bd
- Contao Release Notes 5.3.50
- Contao Release Notes 5.7.12
- NVD Vulnerability Detail CVE-2026-107844
- CVE Program Record CVE-2026-107844
Read the full report for CVE-2026-107844 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)