PT-2026-85501 · Unknown · Grav Admin

·

CVE-2026-85601

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Grav Admin versions prior to 2.0.20
Description Insufficient sanitization of output from the marked.parse() function before it is injected into the Document Object Model (DOM) via Svelte's {@html} directive within the MarkdownEditor and MarkdownModal components. This allows attackers to inject javascript: URI schemes into plugin or theme changelogs, leading to arbitrary code execution in authenticated administrator sessions.
Recommendations Update Grav Admin to version 2.0.20 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85601
GHSA-752R-88J4-VXM3

Affected Products

Grav Admin