CVE-2026-53502EPSS p42.3%
CVE-2026-53502CVE-2026-53502
Description
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.
Scoring
| EPSS | 0.52% probability of exploitation · percentile 42.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-08 |