PT-2026-81136 · Grav · Grav
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 3.9.2
Description
An issue exists in the
sendInvitationEmail() function where untrusted Host headers are not validated when constructing invitation links containing tokens. This allows attackers to manipulate the Host header to poison these links, redirecting users to domains under attacker control. This behavior bypasses the require trusted host protection, as that mechanism only applies to password reset flows.Recommendations
Update Grav to version 3.9.2 or later.
As a temporary mitigation, restrict the use of the
sendInvitationEmail() function until the update is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav