CVE-2026-33171
EUVD-2026-1382220.03.2026, 22:16
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticated Control Panel users could read arbitrary `.json`, `.yaml`, and `.csv` files from the server by manipulating the file dictionary's `filename` configuration parameter in the fieldtype's endpoint. This has been fixed in 5.73.14 and 6.7.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| statamic | statamic | 𝑥 < 5.73.14 |
| statamic | statamic | 6.0.0 ≤ 𝑥 < 6.7.0 |
𝑥
= Vulnerable software versions