GHSA-p279-5wcv-45vq

Suggest an improvement
Source
https://github.com/advisories/GHSA-p279-5wcv-45vq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-p279-5wcv-45vq/GHSA-p279-5wcv-45vq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p279-5wcv-45vq
Aliases
Published
2026-10-07T18:05:38Z
Modified
2026-10-07T18:15:11Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
Details

Summary

The MediaBundle blocks dangerous upload extensions with a blacklist that was matched case-sensitively, while the stored filename was lowercased afterwards. A file uploaded as webshell.pHp therefore bypassed the blacklist and was written to the web-accessible upload directory as webshell.php, where the web server executed it. Any authenticated backend user with access to the media section could obtain remote code execution.

Details

FileHandler::getFilePath() rewrote blacklisted extensions to .txt using a case-sensitive regex, and only then lowercased the extension when building the stored name — so the check ran against the attacker-controlled casing and the normalisation happened after it.

Two further weaknesses contributed:

  • The default blacklist contained only php and htaccess, leaving other server-executable extensions (phtml, php5, phar, shtml, cgi, …) unblocked regardless of casing.
  • Configured blacklist values were interpolated into the regex unescaped.

Impact

An authenticated user with access to the admin media section can upload a file that the web server executes as PHP. The uploaded file is reachable over HTTP without authentication, giving arbitrary code execution as the web server user.

Patches

Fixed in kunstmaan/media-bundle 7.3.2. The extension is now normalised before it is checked and compared with in_array(); the default blacklist is expanded to the full set of server-executable extensions; and a new opt-in allowed_extensions option allows projects to enforce a strict allow-list.

Note that the patch does not rename files already stored on disk. Sites should audit their media upload directory for existing files with an executable extension.

Workarounds

If you cannot upgrade, configure the web server to refuse to execute scripts in the media upload directory (for example a location block in nginx or php_flag engine off in Apache).

Database specific
{
    "cwe_ids": [
        "CWE-434"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T18:05:38Z",
    "nvd_published_at": "2026-10-05T16:17:06Z",
    "severity": "HIGH"
}
References

Affected packages

Packagist / kunstmaan/media-bundle

Package

Name
kunstmaan/media-bundle
Purl
pkg:composer/kunstmaan/media-bundle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.3.2

Affected versions

v1.*
v1.3
v1.3.1
v1.3.2
v1.3.3
v2.*
v2.1
v2.1.1
v2.1.2
v2.1.3
v2.2
v2.2.1
v2.2.2
v2.2.3
v2.2.8
v2.2.9
v2.2.10
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.19
v2.3.20
v2.3.21
v2.3.22
v2.3.23
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.2.0
3.2.1
3.2.1.1
3.2.2
3.2.3
3.2.4
3.2.4.1
3.2.5
3.2.6
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
4.*
4.0.0-RC1
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.2.0
4.2.1
4.2.2
4.2.3
5.*
5.0.0-RC1
5.0.0-RC2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.9
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.7
5.3.8
5.3.9
5.3.10
5.3.11
5.3.12
5.3.13
5.3.14
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
5.4.7
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
5.9.3
5.10.0
5.10.1
5.10.2
5.10.3
5.10.4
5.10.5
5.10.6
5.10.7
6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
6.1.9
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.3.0
6.3.1
6.4.0-alpha1
6.4.0-alpha2
6.4.0
6.4.1
6.4.2
6.4.3
6.4.4
7.*
7.0.0-alpha1
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.1.0-alpha1
7.1.0-alpha2
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-p279-5wcv-45vq/GHSA-p279-5wcv-45vq.json"

Packagist / kunstmaan/bundles-cms

Package

Name
kunstmaan/bundles-cms
Purl
pkg:composer/kunstmaan/bundles-cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.3.2

Affected versions

3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.2.0
3.2.1
3.2.1.1
3.2.2
3.2.3
3.2.4
3.2.4.1
3.2.5
3.2.6
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
4.*
4.0.0-RC1
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.2.0
4.2.1
4.2.2
4.2.3
5.*
5.0.0-RC1
5.0.0-RC2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
5.3.10
5.3.11
5.3.12
5.3.13
5.3.14
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
5.4.7
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
5.9.3
5.10.0
5.10.1
5.10.2
5.10.3
5.10.4
5.10.5
5.10.6
5.10.7
6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
6.1.9
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.3.0
6.3.1
6.4.0-alpha1
6.4.0-alpha2
6.4.0
6.4.1
6.4.2
6.4.3
6.4.4
7.*
7.0.0-alpha1
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.1.0-alpha1
7.1.0-alpha2
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.3.0
7.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-p279-5wcv-45vq/GHSA-p279-5wcv-45vq.json"