PT-2026-78486 · Grav · Grav-Plugin-Api

CVE-2026-62668

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Grav API Plugin versions prior to 1.0.6
Description Insufficient validation of webhook URLs in WebhookController.php and the lack of CURLOPT PROTOCOLS or CURLOPT REDIR PROTOCOLS restrictions in WebhookDispatcher.php allow an account with api.webhooks.write permissions to perform Server-Side Request Forgery (SSRF). This enables the submission of file, dict, gopher, private-network, or link-local targets, allowing the retrieval of local files and delivery response bodies, as well as pivoting requests to internal services or cloud metadata endpoints.
Recommendations Update Grav API Plugin to version 1.0.6.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62668
GHSA-58Q8-F7V4-W2VF

Affected Products

Grav-Plugin-Api