A AegiFlow
MEDIUMCVSS 6.9EPSS 0.3%

CVE-2026-69127

CVE-2026-69127 updated by NVD

Published
2026-09-01
Modified
2026-09-18
EPSS percentile
21%
Sources
github-advisory, nvd

Summary

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistgetkirby/cms4.9.5, 5.5.2

Remediation: Upgrade to 4.9.5 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.