A vulnerability marked as critical has been reported in Craft CMS CMS. This impacts the function
ensurePathIsContained of the component Local File System. The manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-72783. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.