Path Traversal Vulnerability in Grav Web Platform
CVE-2025-66295
8.8HIGH
What is CVE-2025-66295?
Grav, a file-based web platform, is susceptible to a path traversal vulnerability that can be exploited when a user with account creation privileges inputs a username with traversal sequences. This misuse can lead to the YAML account file being written to unintended locations outside of the intended directory, potentially exposing sensitive user information such as email addresses, full names, two-factor authentication secrets, and hashed passwords. This issue has been addressed in version 1.8.0-beta.27.
Affected Version(s)
grav < 1.8.0-beta.27
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
