Bagisto <= 2.4.1 - Unauthenticated Arbitrary File Read
CVE-2026-9506
Verified
Description
Bagisto through 2.4.1 is vulnerable to unauthenticated path traversal in the ImageCache controller. The `original` image-cache route (/cache/original/{filename}) passes the user-supplied filename to getImagePath() without any '..' filtering or realpath containment, allowing a remote unauthenticated attacker to read files outside the intended public image directories (upload/images) - for example the application's composer.json, artisan and other source files.
Severity
High
CVSS Score
8.7
Exploit Probability
2%
Affected Product
bagisto
Published Date
August 7, 2026
Template Author
str4k3r
CVE-2026-9506.yaml
8.7Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE ID:
cve-2026-9506
CWE ID:
cwe-22
Remediation Steps
Fixed in 2.4.2, which adds realpath() containment and '../' sanitisation.