Vulnerability in Grav API Plugin for Grav CMS
CVE-2026-62668

9.4CRITICAL

Key Information:

Vendor

Getgrav

Vendor
CVE Published:
19 August 2026

What is CVE-2026-62668?

The Grav API Plugin, an essential component for Grav CMS offering RESTful access to site content, contains a vulnerability that allows unvalidated webhook URLs. Prior to version 1.0.6, the WebhookController.php only performed minimal syntax validation on the URLs, making it susceptible to file inclusion attacks, enabling malicious actors to access local files and execute unauthorized requests to internal services or cloud metadata endpoints. This flaw is addressed in the updated version 1.0.6, which restricts cURL options to mitigate such security risks.

Affected Version(s)

grav < 2.0.4

grav-plugin-api < 1.0.6

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.