What is CVE-2026-53502?
The CVE-2026-53502 vulnerability in Thumbor, an open-source photo thumbnail service, allows path traversal outside FILE_LOADER_ROOT_PATH via watermark or frame filter input before version 7.8.0 due to improper percent-encoded path validation. Users should upgrade to version 7.8.0 immediately to mitigate the issue.
Azərbaycanca: Thumbor açıq mənbəli şəkil miniatür xidmətində aşkar edilən CVE-2026-53502 zəifliyi, 7.8.0 versiyasından əvvəl `file_loader` komponentində yol doğrulamasını keçərək qapalı qovluqdan kənara çıxmağa imkan verir. Bu, `watermark` və ya `frame` filtrləri vasitəsilə həssas faylların oxunmasına səbəb ola bilər. İstifadəçilər dərhal Thumbor-u 7.8.0 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Thumbor are affected by the CVE-2026-53502 vulnerability?
The CVE-2026-53502 vulnerability affects all versions of Thumbor before version 7.8.0. Users should upgrade to version 7.8.0 immediately to mitigate the issue.
How can an attacker read sensitive files by exploiting CVE-2026-53502?
An attacker can bypass the path validation in the `file_loader` component using `watermark` or `frame` filters, allowing path traversal outside the FILE_LOADER_ROOT_PATH to read sensitive files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.