### TL;DR This vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes (`%2f`), such as nginx, PHP's built-in server or Apache setups that have the option `AllowEncodedSlashes` enabled. It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail
Apache HTTP Server | Nginx
Vulnerability
CVE-2026-75594
GHSA
Update to v4.9.5