{"id":"GHSA-q8cg-5m48-5c25","title":"Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL","summary":"Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL","severity":"medium","cvss":7.6,"cwe":["CWE-79"],"vendor":"getgrav","product":"getgrav/grav","ecosystem":"composer","affected":["getgrav/grav < 2.0.15"],"published":"2026-08-18","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:31:30Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q8cg-5m48-5c25","references":[{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-6qw9-4vv5-jr97"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75831"},{"url":"https://github.com/getgrav/grav/commit/aba291a59cab29ddce491175791888d8d0b65e20"},{"url":"https://www.vulncheck.com/advisories/grav-before-stored-xss-via-audio-video-source-url"},{"url":"https://github.com/advisories/GHSA-q8cg-5m48-5c25"}],"tags":["ghsa","composer"],"ingestedAt":"2026-09-17T18:25:16.052Z","slug":"GHSA-q8cg-5m48-5c25","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-6qw9-4vv5-jr97. This link is maintained to preserve external references.\n\n### Original Description\nGrav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML and JavaScript that executes in viewers' sessions.\n\n## Affected packages\n\n- `getgrav/grav < 2.0.15`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":42,"depthScoreParts":{"impact":41.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}