CVE-2026-82679: diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload
A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown function of the file dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php of the component Widget Editor. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
diem-project diem (Widget Editor)to a version that resolves this vulnerability.Fixed in 5.1.3
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments of diem-project diem up to version 5.1.3 are affected when using the Widget Editor component.
What access does an attacker need?
The attack can be initiated remotely, but it requires low-level privileges. No user interaction is required.
How urgent is remediation?
Public exploit code has been released, which increases the likelihood of exploitation. The project was notified through an issue report but had not responded at the time of publication.