CVE-2026-33171: Statamic
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticated Control Panel users could read arbitrary `.json`, `.yaml`, and `.csv` files from the server by manipulating the file dictionary's `filename` configuration parameter in the fieldtype's endpoint. This has been fixed in 5.73.14 and 6.7.0.
Affected products
- Statamic Statamic: before 5.73.14 (fixed in 5.73.14); from 6.0.0, before 6.7.0 (fixed in 6.7.0)
Published 2026-03-20. Last modified 2026-06-17.