GHSA-hm5p-82g6-m3xh

Suggest an improvement
Source
https://github.com/advisories/GHSA-hm5p-82g6-m3xh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-hm5p-82g6-m3xh/GHSA-hm5p-82g6-m3xh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hm5p-82g6-m3xh
Aliases
  • CVE-2026-24687
Published
2026-01-30T14:43:18Z
Modified
2026-02-03T03:12:28.668803Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Umbraco.Forms has Path Traversal and File Enumeration Vulnerabilities in Linux/Mac
Details

Impact

It's possible for an authenticated backoffice-user to enumerate and traverse paths/files on the systems filesystem and read their contents, on Mac/Linux Umbraco installations using Forms. As Umbraco Cloud runs in a Windows environment, Cloud users aren't affected.

Patches

This issue affects versions 16 and 17 of Umbraco Forms and is patched in 16.4.1 and 17.1.1

Workarounds

If upgrading is not immediately possible, users can mitigate this vulnerability by: * Configuring a WAF or reverse proxy to block requests containing path traversal sequences (../, ..\) in the fileName parameter of the export endpoint * Restricting network access to the Umbraco backoffice to trusted IP ranges * Blocking the /umbraco/forms/api/v1/export endpoint entirely if the export feature is not required

However, upgrading to the patched version is strongly recommended.

References

Credit to Kevin Joensen from Baldur Security for finding this vulnerability

Database specific
{
    "nvd_published_at": "2026-01-29T20:16:10Z",
    "cwe_ids": [
        "CWE-22"
    ],
    "github_reviewed_at": "2026-01-30T14:43:18Z",
    "severity": "MODERATE",
    "github_reviewed": true
}
References

Affected packages

NuGet / Umbraco.Forms

Package

Name
Umbraco.Forms
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.Forms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16.0.0
Fixed
16.4.1

Affected versions

16.*
16.0.0
16.1.0
16.2.0-rc
16.2.0-rc2
16.2.0
16.3.0-rc
16.3.0-rc2
16.3.0
16.3.1
16.4.0-rc
16.4.0-rc2
16.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-hm5p-82g6-m3xh/GHSA-hm5p-82g6-m3xh.json"

NuGet / Umbraco.Forms

Package

Name
Umbraco.Forms
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.Forms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
17.0.0
Fixed
17.1.1

Affected versions

17.*
17.0.0
17.0.1
17.0.2
17.0.3
17.1.0-rc
17.1.0-rc2
17.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-hm5p-82g6-m3xh/GHSA-hm5p-82g6-m3xh.json"