---
id: GHSA-q8cg-5m48-5c25
title: >-
  Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source>
  URL
summary: >-
  Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source>
  URL
severity: medium
cvss: 7.6
cwe:
  - CWE-79
vendor: getgrav
product: getgrav/grav
ecosystem: composer
affected:
  - getgrav/grav < 2.0.15
published: '2026-08-18'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:31:30Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-q8cg-5m48-5c25'
references:
  - url: 'https://github.com/getgrav/grav/security/advisories/GHSA-6qw9-4vv5-jr97'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75831'
  - url: >-
      https://github.com/getgrav/grav/commit/aba291a59cab29ddce491175791888d8d0b65e20
  - url: >-
      https://www.vulncheck.com/advisories/grav-before-stored-xss-via-audio-video-source-url
  - url: 'https://github.com/advisories/GHSA-q8cg-5m48-5c25'
tags:
  - ghsa
  - composer
ingestedAt: '2026-09-17T18:25:16.052Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-6qw9-4vv5-jr97. This link is maintained to preserve external references.

### Original Description
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML and JavaScript that executes in viewers' sessions.

## Affected packages

- `getgrav/grav < 2.0.15`

## Remediation

Refer to the advisory for the patched release.
