Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hmcx-ch82-3fv2 | Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash component |
Wed, 13 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta1:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Mon, 11 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgrav
Getgrav grav |
|
| Vendors & Products |
Getgrav
Getgrav grav |
Mon, 11 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traverse the filesystem to create arbitrary directories and write an index.yaml file containing attacker-controlled data. This vulnerability can lead to unauthorized modification of application behavior, potential data integrity issues, and service disruption in production environments. This vulnerability is fixed in 2.0.0-beta.2. | |
| Title | Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T16:07:54.454Z
Reserved: 2026-04-29T00:31:15.725Z
Link: CVE-2026-42608
Updated: 2026-05-11T16:07:19.935Z
Status : Analyzed
Published: 2026-05-11T16:17:33.207
Modified: 2026-05-13T18:39:05.060
Link: CVE-2026-42608
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:15:40Z
Github GHSA