
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-72783 is a theoretical path traversal weakness (CWE-22) in Craft CMS affecting the ensurePathIsContained function of the Local file system class. It affects Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2. The vulnerability was published on August 11, 2026, with the vendor's own security advisory (GHSA-7hxc-f267-h5q7) originally published July 25, 2026. The CVSS v3.1 base score is 6.2 (Medium), and the CVSS v4.0 base score is 6.9 (Medium) (GitHub Advisory, Github Advisory).
The root cause is a desanitization-style ordering flaw (CWE-22) in the ensurePathIsContained function within Craft CMS's Local file system class. When an asset file is read, the getFileStream method constructs a file path by first validating the input path, then normalizing it, and finally prepending the volume's base directory prefix. Because normalization occurs after validation, a crafted path could pass the initial validation check but, after normalization (e.g., resolving ../ sequences or encoded characters), resolve to a location outside the intended volume directory. The vendor explicitly notes that no directly exploitable scenario has been identified, and the fix is recommended purely as a hardening measure (GitHub Advisory, Github Advisory).
If theoretically exploited, the vulnerability could allow an attacker with local access to read sensitive files outside the intended volume directory, resulting in a high confidentiality impact with no integrity or availability impact. There is no evidence of impact to subsequent systems, and the vendor confirms no exploitable scenario has been discovered in practice. The practical risk is therefore low, but the theoretical exposure involves unauthorized file disclosure from the server's local filesystem (Github Advisory, GitHub Advisory).
There is no known public proof-of-concept exploit, no evidence of in-the-wild exploitation, and no threat actor attribution associated with this vulnerability. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.148%, indicating a very low probability of exploitation within 30 days. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, GitHub Advisory).
Craft CMS users should update to version 5.10.6 or later for 5.x installations, or to version 4.18.2 or later for 4.x installations. The vendor recommends the update as a hardening measure even though no directly exploitable scenario has been identified. No specific configuration-based workarounds have been published (GitHub Advisory, Github Advisory).
The Craft CMS security team (via user angrybrad) published the advisory with a "Low" severity rating and explicitly noted the issue is not directly exploitable, framing the fix as a hardening recommendation. No significant independent researcher commentary, media coverage, or notable community discussion has been identified for this vulnerability (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."