Feed/CVE-2026-56394
CVE-2026-56394LOWCVSS 0.0

CVE-2026-56394

Published Jun 21, 2026·Updated Aug 6, 2026

NVD Description

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.

Affected Packages (1)

craftcms/cmsCOMPOSER
From 4.0.0-RC1
Fixed in = 4.17.6

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free