Описание
Craft CMS has authenticated path traversal in assets/icon, allowing local .svg file read
Summary
An authenticated path traversal in assets/icon allows local SVG file read by passing traversal sequences in the extension parameter. The issue is caused by file existence checks happening before extension validation.
Details
The endpoint:
src/controllers/AssetsController.php:1115-1123actionIcon(string $extension)callsAssets::iconPath($extension)and returnssendFile($path, ...).
In Assets::iconPath():
- Path is built from user-controlled
extension:src/helpers/Assets.php:906-909
- If
file_exists($path)is true, path is returned immediately:src/helpers/Assets.php:910-912
Validation exists in Assets::iconSvg():
preg_match('/^\w+$/', $extension)src/helpers/Assets.php:927-931
However, that validation is only reached if iconPath() does not find a file.
So traversal payloads that resolve to existing .svg files bypass validation and are served by sendFile().
Impact
- Authenticated users can read local .svg files accessible to the application process.
References
Ссылки
- https://github.com/craftcms/cms/security/advisories/GHSA-c43v-4cr8-6mvp
- https://nvd.nist.gov/vuln/detail/CVE-2026-56394
- https://github.com/craftcms/cms/commit/30f5f1a8d6edf0f3a00be72c42c78d9dc7d72d5c
- https://www.vulncheck.com/advisories/craft-cms-authenticated-path-traversal-in-assets-icon-extension-parameter
Пакеты
craftcms/cms
>= 4.0.0-RC1, <= 4.17.6
4.17.7
craftcms/cms
>= 5.0.0-RC1, <= 5.9.12
5.9.13
Связанные уязвимости
Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.