PatchSiren

OctoberCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OctoberCMS CVE published 2026-09-28

CVE-2026-100909

A server-side request forgery vulnerability was found in OctoberCMS, specifically in the `getSourcePathForResize` function of the `ResizeImages.php` file. The vulnerability allows remote attackers to perform server-side request forgery by manipulating the `realSourcePath` argument. The exploit has been made public, and upgrading to version 4.3.5 or 4.4.0 is sufficient to resolve this issue.