Magento vulnerable to path traversal
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Aug 12, 2025 
          to the GitHub Advisory Database
          •
          Updated Oct 21, 2025 
      
  
Package
Affected versions
>= 2.4.9-alpha1, < 2.4.9-alpha2
      >= 2.4.8-beta1, < 2.4.8-p2
      >= 2.4.7-beta1, < 2.4.7-p7
      >= 2.4.6-p1, < 2.4.6-p12
      < 2.4.5-p14
      = 2.4.5
      = 2.4.6
      = 2.4.7
      = 2.4.8
  Patched versions
2.4.9-alpha2
      2.4.8-p2
      2.4.7-p7
      2.4.6-p12
      2.4.5-p14
  Description
        Published by the National Vulnerability Database
      Aug 12, 2025 
    
  
        Published to the GitHub Advisory Database
      Aug 12, 2025 
    
  
        Reviewed
      Oct 21, 2025 
    
  
        Last updated
      Oct 21, 2025 
    
  
Magento versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to modify limited data. Exploitation of this issue does not require user interaction.
References