A vulnerability marked as critical has been reported in globo.com Thumbor up to 7.7.x. This affects an unknown part of the component file_loader. This manipulation causes path traversal.

This vulnerability appears as CVE-2026-53502. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.