PT-2026-51515 · Grav · Grav

·

CVE-2026-56701

·

Published

2026-05-05

·

Updated

2026-06-23

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.0-beta.2
Description An XML external entity (XXE) injection exists in the processing of SVG file uploads. Authenticated attackers can read arbitrary files by injecting XXE payloads via malicious SVG files. This occurs because the application utilizes the simplexml load string() function without disabling the loading of external entities, which allows for the exfiltration of sensitive data.
Recommendations Update to version 2.0.0-beta.2 or later.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56701
GHSA-3446-6MGW-F79P

Affected Products

Grav