GHSA-qh7h-6c7g-x8m6Critical· 5.4▾ MidnightDuplicate Advisory: Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-9ccq-2jfg-qw33. This link is maintained to preserve external references.
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim site's origin (e.g. https://example.com.attacker.tld) can send a request with such a Referer to be treated as same-origin, bypassing the Referer-based origin check.
getgrav/grav < 2.0.16Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-72702LowGrav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match
GHSA-32fw-h446-j4hhHigh· 6.5Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
CVE-2026-56701Medium· 6.5Grav is Vulnerable to XXE via SVG Upload
CVE-2026-72697High· 6.5Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
GHSA-896w-cw95-xq7wHigh· 8.1Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
CVE-2026-72695High· 8.1Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion