
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33686 is a path traversal vulnerability (CWE-22) in the FileUtil class of the code16/sharp PHP CMS package, allowing authenticated attackers to write files outside the intended temporary directory. It affects all versions of code16/sharp prior to 9.20.0 and was disclosed on March 23, 2026, with the patch merged on March 20, 2026. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Sharp Security Advisory).
The root cause lies in src/Utils/FileUtil.php, where the FileUtil::explodeExtension() function extracts a file's extension by splitting the filename at the last dot using strrpos(). The extracted extension is never sanitized — while a normalizeName() function cleans the base filename, it does not process the extension, meaning path separators (e.g., /) injected into the extension survive and are passed directly into the storeAs() storage function. This allows an attacker to craft a filename with a malicious extension containing path traversal sequences, causing files to be written to arbitrary locations on the filesystem. The vulnerability was confirmed in a local proof-of-concept that chained it with CWE-434 (Unrestricted File Upload) to achieve full traversal (GitHub Advisory, Sharp Security Advisory).
Successful exploitation allows an authenticated attacker with low privileges to write arbitrary files outside the intended tmp directory, potentially overwriting critical application files such as .env or other configuration files. This can lead to full compromise of confidentiality (exposure of secrets/credentials), integrity (modification of application behavior), and availability (disruption of service). When chained with an unrestricted file upload vulnerability (CWE-434), the impact is rated High across all three CIA dimensions (GitHub Advisory).
There is no evidence of public exploit code or in-the-wild exploitation at this time, though a local proof-of-concept was developed by the reporter (zaurgsynv) to confirm the traversal when chained with CWE-434 (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.031% (0.00063), placing it in the 9th percentile for exploitation likelihood (GitHub Advisory, Feedly).
FileUtil::explodeExtension() function in src/Utils/FileUtil.php.malicious.../../config/.env or shell../../../public/shell.php, so that the extension portion contains / path separators.normalizeName() function sanitizes only the base name, leaving the traversal sequences in the extension intact.storeAs(), causing the file to be written outside the intended tmp directory to the attacker-controlled path..env to expose or modify credentials/configuration) or, when chained with CWE-434, write a web shell to a publicly accessible directory for remote code execution (GitHub Advisory, Sharp Security Advisory).tmp or storage directories; modifications to .env, config/*.php, or other configuration files with unusual timestamps; new PHP files (potential web shells) in publicly accessible directories (e.g., public/).../, %2F, or other path separator encodings in the extension field; application logs recording storeAs() calls with paths resolving outside the intended storage directory.Content-Disposition filename values containing path traversal sequences.Upgrade code16/sharp to version 9.20.0 or later, which fixes the issue by replacing strrpos() with pathinfo(PATHINFO_EXTENSION) for extension extraction and applying strict regex sanitization to both the base name and extension before passing to storeAs() (Sharp PR #715, GitHub Advisory). As interim mitigations: restrict file upload functionality to the minimum required user roles, enforce strict file system permissions to prevent the web server process from writing outside designated directories, and monitor file system activity for unexpected modifications to critical configuration files.
The vulnerability was reported by security researcher zaurgsynv and covered by The Hacker Wire, which published a technical write-up titled "Sharp CMS – Path Traversal in FileUtil (CVE-2026-33686)" (The Hacker Wire). The disclosure was also noted on Mastodon by The Hacker Wire's account and tracked by several CVE aggregation platforms. No major vendor statements or widespread community controversy have been observed beyond standard advisory publication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."