A vulnerability, which was classified as critical, has been found in getkirby Kirby up to 4.9.4/5.5.1. This impacts the function Kirby\Filesystem\Dir::realpath/Kirby\Filesystem\F::realpath of the file src/Filesystem/Dir.php of the component Media Handler. Performing a manipulation results in path traversal. This vulnerability is identified as CVE-2026-75592. The attack can be initiated remotely.
PHP
Exploit
CVE-2026-75592
VulDB
Apply vendor security patch