PT-2026-81136 · Grav · Grav

·

CVE-2026-56709

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 3.9.2
Description An issue exists in the sendInvitationEmail() function where untrusted Host headers are not validated when constructing invitation links containing tokens. This allows attackers to manipulate the Host header to poison these links, redirecting users to domains under attacker control. This behavior bypasses the require trusted host protection, as that mechanism only applies to password reset flows.
Recommendations Update Grav to version 3.9.2 or later. As a temporary mitigation, restrict the use of the sendInvitationEmail() function until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56709

Affected Products

Grav