<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:getformwork:formwork:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agetformworkformwork/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 00:49:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agetformworkformwork/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Formwork BackupController</title><link>https://feed.craftedsignal.io/briefs/2026-10-formwork-path-traversal/</link><pubDate>Sat, 03 Oct 2026 00:49:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-formwork-path-traversal/</guid><description>Formwork prior to version 2.3.13 contains a path traversal vulnerability in the BackupController component allowing authenticated users to read or delete arbitrary files via base64-encoded payloads.</description><content:encoded><![CDATA[<p>Formwork versions prior to 2.3.13 are vulnerable to a path traversal vulnerability residing within the BackupController component. This vulnerability allows authenticated users who possess backup download or deletion permissions to escape the intended directory structure. By providing a base64-encoded, backslash-separated payload, an attacker can bypass the PHP basename validation logic on Linux-based installations. Successful exploitation permits an authenticated attacker to read sensitive configuration files or delete critical system files, potentially leading to full system compromise or service disruption. Defenders should prioritize updating to version 2.3.13 or later to remediate the underlying flaw in file handling.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-104478 allows an authenticated user to perform arbitrary file reads or deletions. This impacts the integrity and confidentiality of the Formwork installation and underlying server data. If the service is running with elevated privileges, the impact can extend to the broader system environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Formwork to version 2.3.13 or later immediately to patch CVE-2026-104478.</li>
<li>Review access control lists for the administrative panel and restrict backup download and delete permissions to only the most trusted administrative accounts.</li>
<li>Audit web server access logs for requests to the BackupController endpoint that contain unusual, encoded, or backslash-heavy string patterns.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>web-vulnerability</category><category>patch-management</category></item></channel></rss>