Back to list

Kirby: File upload permissions are not checked during processing of chunk data — GHSA-67MX-6WF2-92XP

GitHub · GitHub · GHSA-67MX-6WF2-92XP

ID
GHSA-67MX-6WF2-92XP
Date
Source
GitHub
Vendor
GitHub
Threat
high
CVSS
7.1

Summary

### TL;DR This vulnerability affects all Kirby sites where users of a particular role have access to the REST API (`access.panel` permission is enabled) but no permission to upload any kind of file (`files.create`, `files.replace` and `user/users.update` permissions are all disabled). It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload…

Timeline

Published by source
2026-08-31

Risk context

  • Reported severity or threat level: high.
  • Reported CVSS score: 7.1 out of 10.
  • Review exposure for the affected product or family: composer: getkirby/cms.

Product

composer: getkirby/cms

What to do

General, cautious steps (verify details in the official source):

  • Prioritize patching or mitigation immediately (treat as actively risky).
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Evidence and provenance

Canonical advisory ID
GHSA-67MX-6WF2-92XP
Source
GitHub
Vendor
GitHub
Published by source
2026-08-31
Last source activity
2026-08-31
Additional identifiers
CVE-2026-71415
Curated by
hlukh.ch

Related advisories and connections

These advisories are connected by shared CVE, product, vendor, source, or time signals.