/Vulnerability Library

Bagisto <= 2.4.1 - Unauthenticated Arbitrary File Read

CVE-2026-9506
Verified

Description

Bagisto through 2.4.1 is vulnerable to unauthenticated path traversal in the ImageCache controller. The `original` image-cache route (/cache/original/{filename}) passes the user-supplied filename to getImagePath() without any '..' filtering or realpath containment, allowing a remote unauthenticated attacker to read files outside the intended public image directories (upload/images) - for example the application's composer.json, artisan and other source files.

Severity

High

CVSS Score

8.7

Exploit Probability

2%

Affected Product

bagisto

Published Date

August 7, 2026

Template Author

str4k3r

CVE-2026-9506.yaml
8.7Score

CVSS Metrics

CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE ID:
cve-2026-9506
CWE ID:
cwe-22

References

https://github.com/advisories/GHSA-qhcg-rw5x-vg94https://nvd.nist.gov/vuln/detail/CVE-2026-9506https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0292https://www.ionix.io/threat-center/cve-2026-9506/

Remediation Steps

Fixed in 2.4.2, which adds realpath() containment and '../' sanitisation.