PT-2026-76922 · Grav · Grav
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.15
Description
A path traversal issue exists in the static asset server within the
index.php file. The system employs string prefix matching rather than directory-boundary validation, allowing unauthenticated attackers to access files in sibling directories. This is achieved by requesting directory names that extend the base path string, such as requesting assets-secret when assets is the configured base.Recommendations
Update Grav to version 2.0.15 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav