Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qm7r-wwq7-6f85 | Statamic has a path traversal in file dictionary fieldtype |
Tue, 24 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic statamic
|
|
| CPEs | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Statamic statamic
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic cms |
|
| Vendors & Products |
Statamic
Statamic cms |
Fri, 20 Mar 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticated Control Panel users could read arbitrary `.json`, `.yaml`, and `.csv` files from the server by manipulating the file dictionary's `filename` configuration parameter in the fieldtype's endpoint. This has been fixed in 5.73.14 and 6.7.0. | |
| Title | Statamic has a path traversal in file dictionary fieldtype | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-23T21:41:51.358Z
Reserved: 2026-03-17T22:16:36.718Z
Link: CVE-2026-33171
Updated: 2026-03-23T21:31:38.654Z
Status : Analyzed
Published: 2026-03-20T22:16:28.820
Modified: 2026-03-23T18:46:31.100
Link: CVE-2026-33171
No data.
OpenCVE Enrichment
Updated: 2026-03-25T14:34:28Z
Github GHSA