Sceawere

Vulnerability Detail

CVE-2026-100909UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OctoberCMS SSRF in ResizeImages

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
n/a
Product
OctoberCMS
Attack Type
Server-Side Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-28T05:16:30.067Z",
  "pubdate": "2026-09-28T05:16:30.067Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in OctoberCMS, specifically within the image processing functionality of the system module.\nThe vulnerability is located in the getSourcePathForResize function, which improperly handles input provided via the realSourcePath argument.\nBy manipulating this argument, an unauthenticated remote attacker can coerce the server into making arbitrary HTTP or file system requests.\nThe impact includes the potential to scan internal network infrastructure, access sensitive internal resources, or retrieve local files that are not publicly exposed, depending on the server configuration and PHP execution environment.\nThis vulnerability affects OctoberCMS versions up to 4.1.19, 4.2.25, and 4.3.4.\nExploits for this vulnerability are publicly available, increasing the risk of active exploitation.\nOrganizations using affected versions are strongly advised to upgrade to version 4.3.5 or 4.4.0 immediately to apply the patch identified by commit 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58.",
  "technicalDetails": "The vulnerability resides in the modules/system/classes/ResizeImages.php file, specifically within the getSourcePathForResize function. This function is responsible for resolving the filesystem path of an image source to be processed for resizing operations.\nThe root cause of this vulnerability is the lack of proper input validation and sanitization on the realSourcePath argument. The application fails to effectively verify or restrict the paths provided to the function before using them in file retrieval operations. In many PHP configurations, such operations can be coerced into protocols other than local file access if the underlying library or function supports them (e.g., via wrappers like http://, https://, or other URI schemes), or it may allow path traversal to access sensitive local system files.\nThe attack flow involves a remote actor submitting a crafted request to the OctoberCMS instance that triggers the image resizing logic. By injecting a malicious or crafted URI/path into the realSourcePath parameter, the attacker instructs the ResizeImages class to process a resource outside of the intended directory structure or to initiate a request to an internal target.\nWhen the getSourcePathForResize function processes the malicious realSourcePath, it potentially invokes system calls or library functions that fetch the content of the provided path. Because the system performs this request on behalf of the web server process, the server effectively acts as a proxy for the attacker.\nIf the server's PHP configuration allows the use of wrappers, the attacker can specify remote URLs. This forces the server to initiate outbound network requests to internal services that might otherwise be protected by firewalls, such as internal APIs, metadata services (e.g., cloud instance metadata at 169.254.169.254), or local network appliances. If restricted to the local filesystem, the attacker may bypass directory restrictions to read configuration files, logs, or other sensitive system artifacts that are accessible to the web server user.\nThis vulnerability does not require authentication or specific privilege levels, as the vulnerable endpoint is accessible to remote, unauthenticated users. The post-exploitation impact is significant, as it can lead to full reconnaissance of the internal network architecture, retrieval of sensitive data, and in some contexts, provide a pivot point for further unauthorized actions within the environment.\nThe issue is resolved in versions 4.3.5 and 4.4.0 by implementing stricter validation and canonicalization of the input path to ensure it remains within expected bounds and uses allowed protocols."
}
CVE-2026-100909: OctoberCMS SSRF in ResizeImages (HIGH Severity, CVSS: 7.3) | Sceawere