Host Header Injection Vulnerability in Grav by Get Grav
CVE-2026-56709
8.7HIGH
What is CVE-2026-56709?
Grav prior to version 3.9.2 contains a vulnerability that allows attackers to manipulate Host headers when using the sendInvitationEmail() function. This exploitation can lead to the construction of malicious invitation links that redirect users to unauthorized domains. The vulnerability bypasses fundamental protections, focusing only on password reset flows, thereby exposing users to potential phishing attacks and other malicious activities. It is crucial for users to upgrade to the latest version of Grav to mitigate these risks.
Affected Version(s)
grav 0 < 3.9.2
grav 3.9.2
