A path traversal vulnerability has been identified in Piwigo versions up to 16.3.0, affecting the i.php file within the Image Derivative Handler component. The flaw allows remote attackers to traverse file system paths without authentication. The vulnerability has been publicly disclosed with a proof-of-concept exploit available on GitHub, increasing the risk of active exploitation. Remote exploitation is possible without requiring local access or elevated privileges. The issue stems from improper input validation in the image derivative handling functionality. Organizations using Piwigo up to version 16.3.0 are advised to review and apply any available patches or mitigations. The public availability of the exploit raises the severity and urgency of remediation.