PT-2026-81140 · Grav Cms · Grav Cms

·

CVE-2026-72697

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav CMS versions prior to 2.0.16
Description An issue exists in the media directory() Twig function that fails to validate filesystem paths. Authenticated users with page authoring privileges can provide arbitrary filesystem paths to this function and use the allow-listed filepath accessor on Medium objects to enumerate and read the contents of files outside the intended scope, provided the files match configured media extensions and are accessible by the web server process.
Recommendations Update Grav CMS to version 2.0.16 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72697
GHSA-47CH-6W46-6XM7

Affected Products

Grav Cms