CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-55554

lowcovered by 2 sourcesfirst seen 2026-07-22
Summary The chroot check for local files uses a prefix string check to enforce chroot boundaries. The simple string comparison it performs allows paths like /var/www/root_secret/file.html when chroot is /var/www/root. This allows attacker-controlled document paths/resources to bypass intended local file restrictions. Details The validateLocalUri() method is used to check if a local file is within an allowed chroot directory. After normalization with realpath(), this check is performed with a strpos() comparison: public function validateLocalUri(string $uri) { ... $realfile = realpath(str_replace("file://", "", $uri)); ... foreach ($dirs as $chrootPath) { $chrootPath = realpath($chrootPath); if ($chrootPath !== false && strpos($realfile, $chrootPath) === 0) { $chrootValid = true; Due to the normalization, the $chrootPath string does not have a terminating directory separator (/) appended. Because of this, the strpos() check only validates that $chrootPath is a _prefix_ of $realfile. This allows access to folders with similar names that fall outside of the defined chroot restrictions. For example, a chroot setting of /var/www/ would be normalized to /var/www, removing the trailing /. During strpos(), a $chrootPath of /var/www will also match a $realfile starting with /var/www2, /var/www-admin, or /var/www_backup, despite these being different directories. PoC With a directory structure similar to: /home/dompdf/ |--> web/ |--> pdf.php |--> cat0.jpg |--> web-admin/ |--> cat1.jpg And web-accessible Dompdf functionality similar to the following (poc.html): <?php require 'vendor/autoload.php'; use Dompdf\Dompdf; use Dompdf\Options; $options = new Options(); $options->setChroot(['/home/dompdf/web/']); $dompdf = new Dompdf($options); $dompdf->loadHtml($_POST['html']); $dompdf->render(); $dompdf->stream(); ?> A malicious actor can exploit the vulnerability with the following script: $html = <<<HTML <!DOCTYPE html> <html> <body> <p>within chroot</p> <img src="/ho

⚡ Watch CVE-2026-55554

Get an email if CVE-2026-55554 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-55554

CVE.org record

Embed the live status

CVE-2026-55554 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-55554 status](https://www.csirts.com/badge/CVE-2026-55554)](https://www.csirts.com/cve/CVE-2026-55554)