{"id":"GHSA-jw5g-f64p-6x78","summary":"Camaleon CMS vulnerable to Path Traversal through AWS S3 uploader implementation","details":"Camaleon CMS versions 2.4.5.0 through 2.9.1, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary files from the web server’s filesystem. The issue occurs in the download_private_file functionality when the application is configured to use the CamaleonCmsAwsUploader backend. Unlike the local uploader implementation, the AWS uploader does not validate file paths with valid_folder_path?, allowing directory traversal sequences to be supplied via the file parameter. As a result, any authenticated user, including low-privileged registered users, can access sensitive files such as /etc/passwd. This issue represents a bypass of the incomplete fix for CVE-2024-46987 and affects deployments using the AWS S3 storage backend.","aliases":["CVE-2026-1776"],"modified":"2026-05-05T15:58:51.709196Z","published":"2026-03-10T09:31:46Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-11T00:31:16Z","nvd_published_at":"2026-03-10T07:38:01Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1776"},{"type":"WEB","url":"https://github.com/owen2345/camaleon-cms/pull/1127"},{"type":"WEB","url":"https://github.com/owen2345/camaleon-cms/commit/f54a77e2a7be601215ea1b396038c589a0cab9af"},{"type":"WEB","url":"https://camaleon.website"},{"type":"PACKAGE","url":"https://github.com/owen2345/camaleon-cms"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2026-1776.yml"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/camaleon-cms-aws-uploader-authenticated-path-traversal-arbitrary-file-read"}],"affected":[{"package":{"name":"camaleon_cms","ecosystem":"RubyGems","purl":"pkg:gem/camaleon_cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.5.0"},{"last_affected":"2.9.1"}]}],"versions":["2.4.5","2.4.5.1","2.4.5.10","2.4.5.11","2.4.5.12","2.4.5.13","2.4.5.14","2.4.5.2","2.4.5.3","2.4.5.4","2.4.5.5","2.4.5.7","2.4.5.8","2.4.5.9","2.4.6.0","2.4.6.1","2.4.6.2","2.4.6.3","2.4.6.4","2.4.6.5","2.4.6.6","2.4.6.7","2.4.6.8","2.4.6.9","2.5.0","2.5.1","2.5.2","2.5.3","2.5.3.1","2.6.0","2.6.0.1","2.6.1","2.6.2","2.6.3","2.6.4","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.8.0","2.8.1","2.8.2","2.8.3","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jw5g-f64p-6x78/GHSA-jw5g-f64p-6x78.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}