Vulnerability Description
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media URLs without checking page access permissions or preview tokens, leading to disclosure of draft file contents. This issue is fixed in versions 4.9.4 and 5.4.4.
Related Weaknesses (CWE)
References
- https://github.com/getkirby/kirby/commit/5b9a0ed587575e39156d37fa42ca7f6c73e121f
- https://github.com/getkirby/kirby/commit/bc721080cd8dd4dcb7fc20b3fd0460ee8d0603b
- https://github.com/getkirby/kirby/releases/tag/4.9.4
- https://github.com/getkirby/kirby/releases/tag/5.4.4
- https://github.com/getkirby/kirby/security/advisories/GHSA-89cp-7p28-jffg
FAQ
What is CVE-2026-54004?
CVE-2026-54004 is a documented vulnerability. Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in t...
How severe is CVE-2026-54004?
CVSS scoring is not yet available for CVE-2026-54004. Check NVD for updates.
Is there a patch for CVE-2026-54004?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.