PT-2026-57241 · Grav · Grav
CVE-2026-59193
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.0
Description
An authenticated user with
admin.super privileges can cause a system crash or exhaust disk space by uploading a specially crafted ZIP archive via the Direct Install tool. This occurs because the Installer::unZip() function utilizes ZipArchive::extractTo() without imposing limits on the number of entries, directory depth, or the total uncompressed size of the archive.Recommendations
Update to version 2.0.0.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav