PT-2026-60644 · Grav · Grav
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.4
Description
Authenticated users with
api.webhooks.write permission can create webhooks using unrestricted cURL protocols such as file://, dict://, or gopher://. This allows attackers to trigger webhook events to read local files, access process information, or pivot to internal services.Recommendations
Update to version 2.0.4 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav