{"id":"CVE-2026-56394","aliases":["GHSA-c43v-4cr8-6mvp"],"url":"https://o3.security/vulnerability/CVE-2026-56394","summary":"Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter","details":"### Summary\n\nAn authenticated path traversal in `assets/icon` allows local SVG file read by passing traversal sequences in the `extension` parameter. The issue is caused by file existence checks happening before extension validation.\n\n### Details\nThe endpoint:\n- `src/controllers/AssetsController.php:1115-1123`\n- `actionIcon(string $extension)` calls `Assets::iconPath($extension)` and returns `sendFile($path, ...)`.\n\nIn `Assets::iconPath()`:\n- Path is built from user-controlled `extension`:\n  - `src/helpers/Assets.php:906-909`\n- If `file_exists($path)` is true, path is returned immediately:\n  - `src/helpers/Assets.php:910-912`\n\nValidation exists in `Assets::iconSvg()`:\n  - `preg_match('/^\\w+$/', $extension)`\n  - `src/helpers/Assets.php:927-931`\n\nHowever, that validation is only reached if `iconPath()` does **not** find a file.\nSo traversal payloads that resolve to existing `.svg` files bypass validation and are served by `sendFile()`.\n\n### Impact\n\n- Authenticated users can read local .svg files accessible to the application process.\n\n### References\n\n- https://github.com/craftcms/cms/commit/30f5f1a8d6edf0f3a00be72c42c78d9dc7d72d5c","published":"2026-06-21T13:27:02.445Z","modified":"2026-08-12T03:51:43.378414536Z","cvss":null,"epss":{"score":0.00493,"percentile":0.41252,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.17.7"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.9.13"}],"fix":{"url":"https://github.com/craftcms/cms/commit/30f5f1a8d6edf0f3a00be72c42c78d9dc7d72d5c","label":"craftcms/cms@30f5f1a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56394.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-c43v-4cr8-6mvp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56394"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/craft-cms-authenticated-path-traversal-in-assets-icon-extension-parameter"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/30f5f1a8d6edf0f3a00be72c42c78d9dc7d72d5c"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.378414536Z"}}