Report: CVE-2026-24749 - Silverstripe Assets Module has a DBFile::getURL() permission bypass - 2025 Update
CVE ID :CVE-2026-24749 Published : April 16, 2026, 6:16 p.m. | 46 minutes ago Description :The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file permissions. This usually happens when creating an image variant, for example using a manipulation method like ScaleWidth() or Convert(). Note that if developers use DBFile directly in the $db configuration for a DataObject class that doesn't subclass File, and if they were setting the visibility of those files to