XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash
Critical severity
GitHub Reviewed
Published
May 20, 2026
in
xwiki/xwiki-commons
•
Updated May 26, 2026
Package
Affected versions
>= 4.2-milestone-2, < 16.10.17
>= 17.0.0-rc-1, < 17.4.9
>= 17.5.0, < 17.10.3
>= 18.0.0-rc-1, < 18.1.0-rc-1
Patched versions
16.10.17
17.4.9
17.10.3
18.1.0-rc-1
Description
Published by the National Vulnerability Database
May 20, 2026
Published to the GitHub Advisory Database
May 26, 2026
Reviewed
May 26, 2026
Last updated
May 26, 2026
Impact
It's possible to get access and read configuration files by using URLs such as
http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false.This can apparently be reproduced on Tomcat instances.
Patches
This has been patched in 18.0.0-rc-1, 17.10.3, 17.4.9, 16.10.17.
Workarounds
There is no known workaround, other than upgrading XWiki.
References
For more information
If you have any questions or comments about this advisory:
Attribution
The vulnerability was reported by Michał Kołek.
References