Authenticated Control Panel users could read arbitrary .json, .yaml, and .csv files from the server by manipulating the file dictionary's filename configuration parameter in the fieldtype's endpoint.
This has been fixed in 5.73.14 and 6.7.0.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-18T20:00:42Z",
"nvd_published_at": "2026-03-20T22:16:28Z",
"severity": "MODERATE"
}