CVE-2026-58657

Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the Markdown image resize() media action. Prior media hardening rejects direct ?style= payloads and unsafe attribute() fallbacks, but the resize() action in Excerpts::processMediaActions() writes caller-controlled values directly into the image's styleAttributes. A lower-privileged content editor who can edit page Markdown can store a crafted image URL with semicolon-delimited CSS declarations in the resize parameters, which are rendered into the final <img style=...> attribute when a higher-privileged reviewer/admin views the page or preview. This does not require JavaScript execution but enables UI redress/overlay and content-manipulation attacks (e.g., a full-viewport fixed overlay). Fixed in 2.0.0.
Configurations

No configuration.

History

08 Jul 2026, 15:16

Type Values Removed Values Added
References () https://github.com/getgrav/grav/security/advisories/GHSA-ffmg-hfvg-jhg9 - () https://github.com/getgrav/grav/security/advisories/GHSA-ffmg-hfvg-jhg9 -

08 Jul 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 14:17

Updated : 2026-07-08 15:28


NVD link : CVE-2026-58657

Mitre link : CVE-2026-58657

CVE.ORG link : CVE-2026-58657


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')