Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

CVE-2026-107844: CVE-2026-107844: Path Traversal Vulnerability in Contao ImagesController

CVE-2026-107844: Path Traversal Vulnerability in Contao ImagesController Vulnerability ID: CVE-2026-107844 CVSS Score: 5.3 Published: 2026-10-09 A path traversal vulnerability (CWE-22) in Contao CMS allows unauthent

CVE-2026-107844: Path Traversal Vulnerability in Contao ImagesController

Vulnerability ID: CVE-2026-107844
CVSS Score: 5.3
Published: 2026-10-09

A path traversal vulnerability (CWE-22) in Contao CMS allows unauthenticated remote attackers to bypass directory boundary restrictions in ImagesController and access files within the project directory.

TL;DR

Unauthenticated path traversal in Contao ImagesController permits arbitrary reading of localized files matching allowed extensions and system directory probing.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)
  • CVSS v3.1 Score: 5.3 (Medium)
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Attack Vector: Network (Unauthenticated HTTP/HTTPS GET requests)
  • EPSS Score: 0.00312 (22.18th percentile)
  • Impact: Partial Information Disclosure / Local File Enumeration
  • Exploit Status: Proof of Concept / Public Commit Diffs Available
  • CISA KEV Status: Not Listed

Affected Systems

  • Contao CMS 5.0.0 through 5.3.49
  • Contao CMS 5.4.0-RC1 through 5.7.11
  • Contao CMS: >= 5.0.0, < 5.3.50 (Fixed in: 5.3.50)
  • Contao CMS: >= 5.4.0-RC1, < 5.7.12 (Fixed in: 5.7.12)

Code Analysis

Commit: 867c055

Fix path traversal vulnerability in ImagesController by checking Path::isBasePath()

Exploit Details

Mitigation Strategies

  • Upgrade Contao CMS dependencies to fixed maintenance releases 5.3.50 or 5.7.12.
  • Enforce Web Application Firewall (WAF) filtering on HTTP request URI parameters for path traversal sequences.
  • Restrict 'contao.image.valid_extensions' configuration to essential image asset types only.
  • Disable application debug mode in production deployment environments to avoid absolute path disclosure.

Remediation Steps:

  1. Run 'composer update contao/contao --with-dependencies' in project root environments.
  2. Verify that contao package versions resolved match >= 5.3.50 or >= 5.7.12.
  3. Clear Symfony application caches using 'php vendor/bin/contao-console cache:clear'.
  4. Execute automated or unit tests against ImagesController routes to confirm traversal attempts return HTTP 404.

References

Read the full report for CVE-2026-107844 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.