{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/formwork--2.3.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:getformwork:formwork:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-104478"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Formwork (\u003c 2.3.13)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","web-vulnerability","patch-management"],"_cs_type":"advisory","_cs_vendors":["Formwork"],"content_html":"\u003cp\u003eFormwork versions prior to 2.3.13 are vulnerable to a path traversal vulnerability residing within the BackupController component. This vulnerability allows authenticated users who possess backup download or deletion permissions to escape the intended directory structure. By providing a base64-encoded, backslash-separated payload, an attacker can bypass the PHP basename validation logic on Linux-based installations. Successful exploitation permits an authenticated attacker to read sensitive configuration files or delete critical system files, potentially leading to full system compromise or service disruption. Defenders should prioritize updating to version 2.3.13 or later to remediate the underlying flaw in file handling.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-104478 allows an authenticated user to perform arbitrary file reads or deletions. This impacts the integrity and confidentiality of the Formwork installation and underlying server data. If the service is running with elevated privileges, the impact can extend to the broader system environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Formwork to version 2.3.13 or later immediately to patch CVE-2026-104478.\u003c/li\u003e\n\u003cli\u003eReview access control lists for the administrative panel and restrict backup download and delete permissions to only the most trusted administrative accounts.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for requests to the BackupController endpoint that contain unusual, encoded, or backslash-heavy string patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T00:49:47Z","date_published":"2026-10-03T00:49:47Z","id":"https://feed.craftedsignal.io/briefs/2026-10-formwork-path-traversal/","summary":"Formwork prior to version 2.3.13 contains a path traversal vulnerability in the BackupController component allowing authenticated users to read or delete arbitrary files via base64-encoded payloads.","title":"Path Traversal Vulnerability in Formwork BackupController","url":"https://feed.craftedsignal.io/briefs/2026-10-formwork-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Formwork (\u003c 2.3.13)","version":"https://jsonfeed.org/version/1.1"}