PT-2026-50725 · Packagist+2 · Getkirby/Cms+1
CVE-2026-54004
·
Published
2026-06-18
·
Updated
2026-07-09
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kirby versions prior to 4.9.4
Kirby versions prior to 5.4.4
Description
Kirby sites with the
content.fileRedirects option enabled allow unauthenticated users to access clean file URLs for files stored in top-level draft pages. The system redirects these requests to physical media URLs without verifying page access permissions or requiring a valid preview token. This missing authorization can lead to the disclosure of sensitive draft file contents. A successful exploit requires the attacker to know the full clean file URL path to the draft page and file. This issue does not affect draft files nested under other pages, as clean file URLs are not supported for nested drafts.Recommendations
Update Kirby to version 4.9.4 or later.
Update Kirby to version 5.4.4 or later.
As a temporary mitigation, disable the
content.fileRedirects option.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getkirby/Cms
Kirby