Path Traversal Vulnerability in Grav Web Platform
CVE-2025-66295
8.8HIGH
What is CVE-2025-66295?
Grav, a file-based web platform, is susceptible to a path traversal vulnerability that can be exploited when a user with account creation privileges inputs a username with traversal sequences. This misuse can lead to the YAML account file being written to unintended locations outside of the intended directory, potentially exposing sensitive user information such as email addresses, full names, two-factor authentication secrets, and hashed passwords. This issue has been addressed in version 1.8.0-beta.27.
Affected Version(s)
grav < 1.8.0-beta.27
