{"id":"CVE-2026-53502","aliases":["GHSA-cj54-hpcc-gj6h","PYSEC-2026-3618"],"url":"https://o3.security/vulnerability/CVE-2026-53502","summary":"Thumbor has path traversal via post-validation URL decoding bypass in file_loader","details":"Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.","published":"2026-07-31T19:03:16.522Z","modified":"2026-09-10T03:30:47.865462768Z","cvss":null,"epss":{"score":0.00357,"percentile":0.2903,"asOf":"2026-09-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"thumbor","fixedVersion":"7.8.0"}],"fix":{"url":"https://github.com/thumbor/thumbor/commit/3b986d13677b30fe6651c8c72ebb25957ac0a40d","label":"thumbor/thumbor@3b986d1"},"references":[{"type":"WEB","url":"https://github.com/thumbor/thumbor/releases/tag/7.8.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53502.json"},{"type":"ADVISORY","url":"https://github.com/thumbor/thumbor/security/advisories/GHSA-cj54-hpcc-gj6h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53502"},{"type":"FIX","url":"https://github.com/thumbor/thumbor/commit/3b986d13677b30fe6651c8c72ebb25957ac0a40d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:30:47.865462768Z"}}