Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.
CVSS
No CVSS.
References
Configurations
No configuration.
History
31 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/thumbor/thumbor/security/advisories/GHSA-cj54-hpcc-gj6h - |
31 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-31 19:17
Updated : 2026-07-31 20:16
NVD link : CVE-2026-53502
Mitre link : CVE-2026-53502
CVE.ORG link : CVE-2026-53502
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
