
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33171 is a path traversal vulnerability in Statamic CMS that allows authenticated Control Panel users to read arbitrary .json, .yaml, and .csv files from the server by manipulating the filename configuration parameter in the file dictionary fieldtype's endpoint. It affects all Statamic versions prior to 5.73.14 (v5 branch) and versions 6.0.0 through 6.6.x (prior to 6.7.0). The vulnerability was published on March 17, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Github Advisory, github.com).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal): the file dictionary fieldtype's endpoint does not properly sanitize or restrict the filename configuration parameter supplied by the user, allowing path traversal sequences to escape the intended directory boundary. An authenticated attacker can craft a request to the fieldtype's endpoint with a manipulated filename value (e.g., containing ../ sequences) to reference files outside the permitted directory. Exploitation requires only low-privilege authenticated access to the Statamic Control Panel and no user interaction, making it straightforward for any valid CP user to abuse (Github Advisory, github.com).
Successful exploitation allows an authenticated Control Panel user to read arbitrary .json, .yaml, and .csv files from the server's filesystem, which may include application configuration files, environment files, API keys, database credentials, and other sensitive data stored in those formats. There is no impact on integrity or availability; the vulnerability is limited to confidentiality. However, disclosure of credentials or configuration secrets could enable further compromise, privilege escalation, or lateral movement within the environment (Github Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.022% (6th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to authenticated Control Panel users, which limits the attacker pool but does not eliminate insider or compromised-account risk.
filename configuration parameter to include path traversal sequences (e.g., ../../config/database.yaml or ../../.env.json).filename without proper sanitization and returns the contents of the targeted .json, .yaml, or .csv file.../, %2e%2e%2f, or encoded variants) in the filename parameter.filename values referencing files outside expected directories; repeated access attempts to configuration-related paths (e.g., config/, .env, database)..json, .yaml, or .csv files may be updated unexpectedly.Upgrade Statamic CMS to version 5.73.14 (for the v5 branch) or 6.7.0 (for the v6 branch), which contain the fix for this vulnerability (Github Advisory, github.com). As interim mitigations, restrict Control Panel access to trusted users and trusted network segments only, and monitor CP activity for suspicious file access patterns. No official configuration-only workaround has been published by the vendor.
A Medium article by researcher spbavarva (credited as the reporter) was published covering CVE-2026-33171, providing a write-up on the path traversal issue in Statamic CMS (Github Advisory). The vulnerability received routine coverage from vulnerability tracking services such as VulDB, cvefeed.io, and radar.offseq.com. Community reaction has been limited given the moderate severity and authentication requirement.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."