CVE-2026-107844 Contao 路径遍历信息泄露漏洞
影响未授权攻击者可读取项目目录下特定扩展名文件并探测路径
Contao CMS 的 ImagesController 在处理用户可控的 {path} 参数时,使用 Path::join() 拼接配置的图片目标目录,但未通过 Path::isBasePath() 校验规范化后的路径是否仍位于该目录内。攻击者可通过编码的父目录跳转段构造请求,借助 BinaryFileResponse 返回项目目录下符合 contao.image.valid_extensions 允许扩展名的文件。
影响范围
Contao 5.0.0 至 5.3.50 之前版本,以及 5.7.12 之前版本;修复版本为 5.3.50 和 5.7.12。
漏洞详情
漏洞类型为路径遍历(目录穿越)。成因是路径拼接后缺少规范化路径的基目录校验,导致 ../ 等父目录段可逃逸出预期目录。利用方式为发送包含编码父目录段的未授权 HTTP 请求,读取项目目录下允许扩展名的文件,并可探测任意路径是否存在;调试响应还可能泄露绝对文件系统路径。
利用条件与风险
利用无需认证,但仅能读取扩展名受 contao.image.valid_extensions 限制的文件,且上传目录以下路径未被证实可读,实际危害以信息泄露和路径探测为主。
修复建议
升级至 Contao 5.3.50 或 5.7.12 及以上版本。临时缓解可限制 contao.image.valid_extensions 允许的扩展名、关闭调试模式,并在反向代理层拦截含父目录跳转段的请求。
Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12.