PT-2026-67411 · Grav Cms · Grav Cms

·

CVE-2026-69089

·

Published

2026-07-21

·

Updated

2026-08-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav CMS version 2.0.10
Description A path traversal issue exists in the ImageMedium::watermark() function, which passes an unsanitized $image argument to RocketThemeToolboxResourceLocatorUniformResourceLocator::findResource(). The file:// scheme branch only performs lexical collapse of .. segments without verifying the real path or containment. This allows an editor using Markdown image syntax with traversal sequences to include arbitrary image files from outside the media sandbox into a carrier image. The resulting image is cached and served via a public, unauthenticated URL, leading to the disclosure of files to anonymous visitors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11003
CVE-2026-69089
GHSA-W3F4-8PJ2-599W

Affected Products

Grav Cms