Path Traversal Vulnerability in Grav by GetGrav
CVE-2026-74907
8.2HIGH
What is CVE-2026-74907?
Grav versions prior to 2.0.15 have a vulnerability in the static asset server that allows unauthenticated attackers to exploit path traversal. By utilizing a crafted request with directory names that expand beyond the configured base path, an attacker can access files located in sibling directories. This flaw arises due to improper directory-boundary validation, posing a significant risk to sensitive information stored within the server's file system.
Affected Version(s)
grav 0 < 2.0.15
grav 2.0.15
