Path Traversal Vulnerability in Grav CMS by GetGrav
CVE-2026-69089

8.7HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-69089?

Grav CMS version 2.0.10 contains a path traversal flaw in the ImageMedium::watermark() function. This vulnerability arises when unsanitized image paths are passed to the resource location routine, allowing unauthorized access to files outside the intended media sandbox. If Markdown syntax includes traversal sequences, attackers can potentially expose sensitive files by tricking the system into assembling illegitimate images. These unauthorized files may be served from public URLs, presenting significant privacy and security risks to users.

Affected Version(s)

grav 0 < 2.0.11

grav 2.0.11

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nihaddhuseynli
.