๐Ÿ” CVE Alert

CVE-2026-41887

MEDIUM 4.9

Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restricted the @import and data-uri() LESS features in the custom_less setting, but the same restriction was never applied to other settings registered as LESS config variables (for example theme_primary_color and theme_secondary_color, as well as any key registered via Extend\Settings::registerLessConfigVar()). Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary @import directive into the compiled forum.css. Because the underlying LESS parser honours @import (inline) '<path>', an attacker can read arbitrary files reachable by the PHP process (local file inclusion) or trigger outbound HTTP(S) requests (server-side request forgery). This issue has been patched in versions 1.8.16 and 2.0.0-rc.1.

CWE CWE-22 CWE-918
Vendor flarum
Product framework
Published May 8, 2026
Last Updated May 8, 2026
Stay Ahead of the Next One

Get instant alerts for flarum framework

Be the first to know when new medium vulnerabilities affecting flarum framework are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

flarum / framework
< 1.8.16 >= 2.0.0-beta.1, < 2.0.0-rc.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/flarum/framework/security/advisories/GHSA-xjvc-pw2r-6878 github.com: https://github.com/flarum/framework/commit/2d90a1f19f0e46f8c7e1b07c48ba74b5e38f8410 github.com: https://github.com/flarum/framework/releases/tag/v1.8.16 github.com: https://github.com/flarum/framework/releases/tag/v2.0.0-rc.1