CVE-2026-45368
Description
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components did not filter out malicious URL values that resolve to script execution. The vulnerability affects four first-party Kirby renderers that produce ` output from editor-supplied field values: the (link: …) KirbyTag, the link: parameter of the (image: …) KirbyTag when it does not resolve to a known file or self, the link field of the built-in image block, and the HTML importer for the blocks field (which accepted the same malicious input as the image block link field). While simple avascript: URLs were already deactivated by treating them as a relative path and prepending a single slash to the URL, the use of URLs of the format javascript://x%0A… bypasses this protection. The vbscript:, data:, livescript:, mocha: and jar:` schemes are affected by the same underlying gap. This issue has been fixed in versions 4.9.1 and 5.4.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getkirby/cmsPackagist | < 4.9.1 | 4.9.1 |
getkirby/cmsPackagist | >= 5.0.0, < 5.4.1 | 5.4.1 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Kirby CMS: Six High-Severity CVEs Disclosed in 18-Hour BatchVypr Intelligence · May 27, 2026