PKSA-m1sp-3j4c-yg88 Security Advisory
-
[HIGH] Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
PKSA-m1sp-3j4c-yg88 CVE-2026-41325 GHSA-6gqr-mx34-wh8r
Affected package: getkirby/cms
Affected version: >=5.0.0,<5.4.0|<4.9.0
Reported by:
GitHub