Path Traversal Vulnerability in Grav CMS by GetGrav
CVE-2026-69089
8.7HIGH
What is CVE-2026-69089?
Grav CMS version 2.0.10 contains a path traversal flaw in the ImageMedium::watermark() function. This vulnerability arises when unsanitized image paths are passed to the resource location routine, allowing unauthorized access to files outside the intended media sandbox. If Markdown syntax includes traversal sequences, attackers can potentially expose sensitive files by tricking the system into assembling illegitimate images. These unauthorized files may be served from public URLs, presenting significant privacy and security risks to users.
Affected Version(s)
grav 0 < 2.0.11
grav 2.0.11
