Statamic has a path traversal in file dictionary fieldtype
Package
Affected versions
>= 6.0.0-alpha.1, < 6.7.0
< 5.73.14
Patched versions
6.7.0
5.73.14
Description
Published to the GitHub Advisory Database
Mar 18, 2026
Reviewed
Mar 18, 2026
Last updated
Mar 18, 2026
Impact
Authenticated Control Panel users could read arbitrary
.json,.yaml, and.csvfiles from the server by manipulating the file dictionary'sfilenameconfiguration parameter in the fieldtype's endpoint.Patches
This has been fixed in 5.73.14 and 6.7.0.
References