IBX-1392: Image filenames sanitizationGHSA-44m4-9cjp-j587
GHSA-44m4-9cjp-j587 is a security vulnerability in ezsystems/ezpublish-kernel. A fix is available for ezsystems/ezpublish-kernel — see the affected versions and patch details below.
Real-World Exposure
ezsystems/ezpublish-kernelReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
ezsystems/ezpublish-kernel versions 7.5.* before 7.5.26 are vulnerable to certain injection attacks and unauthorized access to some image files.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | ezsystems/ezpublish-kernel | ≥ 7.5.0&&< 7.5.26 | 7.5.26composer require ezsystems/ezpublish-kernel:^7.5.26 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for ezsystems/ezpublish-kernel, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update ezsystems/ezpublish-kernel to 7.5.26 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-44m4-9cjp-j587 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Frequently Asked Questions
Is GHSA-44m4-9cjp-j587 in your dependencies?
Find it across Packagist, including transitive dependencies.