CVE-2026-53502
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.
| CWE | CWE-22 |
| Vendor | thumbor |
| Product | thumbor |
| Published | Jul 31, 2026 |
| Last Updated | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for thumbor thumbor
Be the first to know when new unknown vulnerabilities affecting thumbor thumbor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
thumbor / thumbor
< 7.8.0