SCA: security update for contao/core-bundle (GHSA-mrvp-7wmx-5m4h)

medium Tenable Self-Hosted Container Security Plugin ID 474063

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-
controlled {path} parameter to the configured image target directory with Path::join() but does not use
Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated
request containing encoded parent-directory segments can therefore return files under the project
directory through BinaryFileResponse when their names use an extension allowed by
contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug
responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to
be readable. This issue is fixed in versions 5.3.50 and 5.7.12. (CVE-2026-107844)

Solution

Update the contao/core-bundle library and its related packages to version 5.3.50 or later.

See Also

https://github.com/advisories/GHSA-mrvp-7wmx-5m4h

Plugin Details

Severity: Medium

ID: 474063

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/10/2026

Updated: 10/10/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-107844

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 10/9/2026

Reference Information

CVE: CVE-2026-107844

cwe: CWE-22