PT-2026-71989 · Grav · Grav
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.13
Description
Insufficient validation of backup profile root paths allows users with profile editor access to archive directories outside the
GRAV ROOT directory, provided the paths are not included in the hard-coded deny-list. This can be exploited using traversal paths to expose sensitive files from system locations such as /opt, /mnt, or /srv.Recommendations
Update Grav to version 2.0.13 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav