PT-2026-76922 · Grav · Grav

·

CVE-2026-74907

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.15
Description A path traversal issue exists in the static asset server within the index.php file. The system employs string prefix matching rather than directory-boundary validation, allowing unauthenticated attackers to access files in sibling directories. This is achieved by requesting directory names that extend the base path string, such as requesting assets-secret when assets is the configured base.
Recommendations Update Grav to version 2.0.15 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74907
GHSA-4V9Q-P283-QC2M

Affected Products

Grav