XML External Entity Injection Vulnerability in Grav by GetGrav
CVE-2026-56701
7.1HIGH
What is CVE-2026-56701?
Grav prior to version 2.0.0-beta.2 is susceptible to an XML External Entity (XXE) injection vulnerability that arises during the processing of SVG file uploads. This security flaw allows authenticated attackers to exploit the application by leveraging simplexml_load_string without disabling external entity loading. As a result, attackers can inject malicious SVG files containing XXE payloads, potentially exposing sensitive data by reading arbitrary files on the server. It is essential for users and admins of Grav to upgrade to the latest version to mitigate this risk.
Affected Version(s)
Grav 0 < 2.0.0-beta.2
Grav 2.0.0-beta.2
