๐Ÿ” CVE Alert

CVE-2026-53502

UNKNOWN 0.0

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.

CWE CWE-22
Vendor thumbor
Product thumbor
Published Jul 31, 2026
Last Updated Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for thumbor thumbor

Be the first to know when new unknown vulnerabilities affecting thumbor thumbor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

thumbor / thumbor
< 7.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/thumbor/thumbor/security/advisories/GHSA-cj54-hpcc-gj6h github.com: https://github.com/thumbor/thumbor/commit/3b986d13677b30fe6651c8c72ebb25957ac0a40d github.com: https://github.com/thumbor/thumbor/releases/tag/7.8.0