GHSA-4v26-phwj-4v5rHighCVSS 7.1

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows...

Published
October 3, 2026
Last Modified
October 3, 2026

🔗 CVE IDs covered (1)

📋 Description

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.

🔗 References (5)