CVE-2026-104478 Details
Description
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
A path traversal vulnerability has been identified in Formwork versions prior to 2.3.13, specifically within the BackupController. This vulnerability allows authenticated panel users to read or delete arbitrary files. Attackers with permissions to download or delete backups can exploit this issue by sending a base64-encoded, backslash-separated traversal payload that bypasses the PHP basename function on Linux, enabling access to files outside the designated backup directory.
Users are advised to update to Formwork version 2.3.13 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getformwork/formwork | [email protected] | ProductSource CodeVendor |
| https://github.com/getformwork/formwork/commit/89e7821a6fcee89474cd401b3dde0c1dccb0687f | [email protected] | Source CodeVendor |
| https://www.vulncheck.com/advisories/formwork-before-2.3.13-path-traversal-via-backupcontroller-download-and-delete | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Formwork | >= 0, < 2.3.13 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 3, 2026 | New CVE Received | [email protected] |
Volerion