VYPR
High severityGHSA Advisory· Published Jul 16, 2026· Updated Jul 18, 2026

CVE-2026-45368

CVE-2026-45368

Description

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components did not filter out malicious URL values that resolve to script execution. The vulnerability affects four first-party Kirby renderers that produce ` output from editor-supplied field values: the (link: …) KirbyTag, the link: parameter of the (image: …) KirbyTag when it does not resolve to a known file or self, the link field of the built-in image block, and the HTML importer for the blocks field (which accepted the same malicious input as the image block link field). While simple avascript: URLs were already deactivated by treating them as a relative path and prepending a single slash to the URL, the use of URLs of the format javascript://x%0A… bypasses this protection. The vbscript:, data:, livescript:, mocha: and jar:` schemes are affected by the same underlying gap. This issue has been fixed in versions 4.9.1 and 5.4.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
getkirby/cmsPackagist
< 4.9.14.9.1
getkirby/cmsPackagist
>= 5.0.0, < 5.4.15.4.1

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

1