CVE-2026-69127: Kirby: System path exposure from error messages in the REST API
Some internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors.
In affected releases, the REST API error handler did not sanitize error messages for sensitive information.
This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default content.salt or prepare specialized attacks.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-69127 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →