CVE-2026-33171 | Statamic CMS up to 5.73.13/6.6.x Configuration Parameter path traversal (GHSA-qm7r-wwq7-6f85)
A vulnerability has been found in Statamic CMS up to 5.73.13/6.6.x and classified as critical. This affects an unknown part of the component Configuration Parameter Handler. The manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-33171. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.