GHSA-jgcf-rf45-2f8v

Suggest an improvement
Source
https://github.com/advisories/GHSA-jgcf-rf45-2f8v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jgcf-rf45-2f8v/GHSA-jgcf-rf45-2f8v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jgcf-rf45-2f8v
Aliases
Published
2026-04-16T20:40:37Z
Modified
2026-05-05T16:09:18Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Silverstripe Assets Module has a DBFile::getURL() permission bypass
Details

Impact

Images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file permissions.

This usually happens when creating an image variant, for example using a manipulation method like ScaleWidth() or Convert().

Note that if you use DBFile directly in the $db configuration for a DataObject class that doesn't subclass File, and if you were setting the visibility of those files to "protected", those files will now need an explicit access grant to be accessed. If you do not want to explicitly provide access grants for these files (i.e. you want these files to be accessible by default), you should use the "public" visibility.

Reported by

Restruct web & apps

Database specific
{
    "cwe_ids": [
        "CWE-266",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-16T20:40:37Z",
    "nvd_published_at": "2026-04-16T18:16:44Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / silverstripe/assets

Package

Name
silverstripe/assets
Purl
pkg:composer/silverstripe/assets

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.5

Affected versions

1.*
1.0.0-alpha6
1.0.0-alpha7
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0
1.0.1-rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.1.0-rc1
1.1.0-rc2
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0-beta1
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.3.0-rc1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0-rc1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0-alpha1
1.5.0-rc1
1.5.0-rc2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0-beta1
1.6.0-rc1
1.6.0
1.6.1
1.7.0-beta1
1.7.0-rc1
1.7.0
1.7.1
1.8.0-beta1
1.8.0-rc1
1.8.0
1.9.0-alpha1
1.9.0-beta1
1.9.0-rc1
1.9.0
1.10.0-beta1
1.10.0-rc1
1.10.0
1.10.1
1.11.0-beta1
1.11.0-rc1
1.11.0
1.11.1
1.12.0-beta1
1.12.0-rc1
1.12.0
1.12.1
1.13.0-beta1
1.13.0-rc1
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.13.7
1.13.8
1.13.9
1.13.10
1.13.11
1.13.12
2.*
2.0.0-alpha1
2.0.0-beta1
2.0.0-rc1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0-beta1
2.1.0-rc1
2.1.0
2.1.1
2.1.2
2.2.0-beta1
2.2.0-rc1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0-beta1
2.3.0-rc1
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0-beta1
2.4.0-rc1
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jgcf-rf45-2f8v/GHSA-jgcf-rf45-2f8v.json"

Packagist / silverstripe/assets

Package

Name
silverstripe/assets
Purl
pkg:composer/silverstripe/assets

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.1.3

Affected versions

3.*
3.0.0
3.0.1
3.1.0-beta1
3.1.0-rc1
3.1.0
3.1.1
3.1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jgcf-rf45-2f8v/GHSA-jgcf-rf45-2f8v.json"