getgrav/grav Security Advisories for 2.0.0-beta.3 (10)
-
[HIGH] Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
PKSA-p6yn-thc9-dbs3 CVE-2026-62669 GHSA-7mgc-c7pq-3rr3
Affected version: <2.0.4
Reported by:
GitHub -
[MEDIUM] Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)
PKSA-sq15-xbtt-m678 CVE-2026-61842 GHSA-mc5q-6hpj-rp7j
Affected version: <2.0.2
Reported by:
GitHub -
[MEDIUM] Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits
PKSA-2vrn-cxz9-yg23 CVE-2026-61690 GHSA-928x-9mpw-8h56
Affected version: <2.0.1
Reported by:
GitHub -
[HIGH] Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
PKSA-1q9r-bgms-91mf CVE-2026-64850 GHSA-fj2p-qj2f-74v5
Affected version: <2.0.7
Reported by:
GitHub -
[MEDIUM] Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin
PKSA-rjzr-vkvg-cvmf GHSA-8hgv-xc77-jmcr
Affected version: <=2.0.19
Reported by:
GitHub -
[HIGH] Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
PKSA-wh99-p4gt-7bkp CVE-2026-62673 GHSA-vwg3-w8w3-pc79
Affected version: <2.0.4
Reported by:
GitHub -
[HIGH] Grav: Unauthenticated denial of service via unbounded image derivative dimensions
PKSA-pv12-m6cp-m9cd CVE-2026-53653 GHSA-4x9g-vw65-vvf9
Affected version: <1.7.53|>=2.0.0-beta.1,<2.0.0-rc.8
Reported by:
GitHub -
[MEDIUM] Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
PKSA-p98m-jfx1-qxw4 CVE-2026-55890 GHSA-pmf8-g7c8-7v54
Affected version: <=2.0.0-rc.8
Reported by:
GitHub -
[HIGH] Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()
PKSA-jw9z-qj9h-1drk CVE-2026-44738 GHSA-j274-39qw-32c9
Affected version: <=2.0.0-rc.1
Reported by:
GitHub -
[HIGH] Low-privileged Grav API users can create super-admin accounts via blueprint-upload
PKSA-jtpz-17pm-t9v9 CVE-2026-42844 GHSA-6xx2-m8wv-756h
Affected version: <2.0.0-beta.4
Reported by:
GitHub