XML External Entity Injection Vulnerability in Grav by GetGrav
CVE-2026-56701

7.1HIGH

Key Information:

Vendor

Grav

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-56701?

Grav prior to version 2.0.0-beta.2 is susceptible to an XML External Entity (XXE) injection vulnerability that arises during the processing of SVG file uploads. This security flaw allows authenticated attackers to exploit the application by leveraging simplexml_load_string without disabling external entity loading. As a result, attackers can inject malicious SVG files containing XXE payloads, potentially exposing sensitive data by reading arbitrary files on the server. It is essential for users and admins of Grav to upgrade to the latest version to mitigate this risk.

Affected Version(s)

Grav 0 < 2.0.0-beta.2

Grav 2.0.0-beta.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.