PT-2026-50725 · Packagist+2 · Getkirby/Cms+1

CVE-2026-54004

·

Published

2026-06-18

·

Updated

2026-07-09

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kirby versions prior to 4.9.4 Kirby versions prior to 5.4.4
Description Kirby sites with the content.fileRedirects option enabled allow unauthenticated users to access clean file URLs for files stored in top-level draft pages. The system redirects these requests to physical media URLs without verifying page access permissions or requiring a valid preview token. This missing authorization can lead to the disclosure of sensitive draft file contents. A successful exploit requires the attacker to know the full clean file URL path to the draft page and file. This issue does not affect draft files nested under other pages, as clean file URLs are not supported for nested drafts.
Recommendations Update Kirby to version 4.9.4 or later. Update Kirby to version 5.4.4 or later. As a temporary mitigation, disable the content.fileRedirects option.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54004
GHSA-89CP-7P28-JFFG

Affected Products

Getkirby/Cms
Kirby