CVE-2026-42608

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traverse the filesystem to create arbitrary directories and write an index.yaml file containing attacker-controlled data. This vulnerability can lead to unauthorized modification of application behavior, potential data integrity issues, and service disruption in production environments. This vulnerability is fixed in 2.0.0-beta.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:2.0.0:beta1:*:*:*:*:*:*

History

13 May 2026, 18:39

Type Values Removed Values Added
References () https://github.com/getgrav/grav/security/advisories/GHSA-hmcx-ch82-3fv2 - () https://github.com/getgrav/grav/security/advisories/GHSA-hmcx-ch82-3fv2 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Getgrav grav
Getgrav
CPE cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:2.0.0:beta1:*:*:*:*:*:*

11 May 2026, 17:16

Type Values Removed Values Added
References () https://github.com/getgrav/grav/security/advisories/GHSA-hmcx-ch82-3fv2 - () https://github.com/getgrav/grav/security/advisories/GHSA-hmcx-ch82-3fv2 -

11 May 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 16:17

Updated : 2026-05-13 18:39


NVD link : CVE-2026-42608

Mitre link : CVE-2026-42608

CVE.ORG link : CVE-2026-42608


JSON object : View

Products Affected

getgrav

  • grav
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')