Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling directories by exploiting directory names that extend the base path string, such as requesting assets-secret when assets is the configured base.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling directories by exploiting directory names that extend the base path string, such as requesting assets-secret when assets is the configured base. | |
| Title | Grav before 2.0.15 Path Traversal via plugin-asset-map.php | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-18T11:19:38.302Z
Updated: 2026-08-18T13:36:23.049Z
Reserved: 2026-08-17T10:48:45.738Z
Link: CVE-2026-74907
Updated: 2026-08-18T12:51:21.625Z
Status : Deferred
Published: 2026-08-18T12:19:31.047
Modified: 2026-09-08T20:32:39.347
Link: CVE-2026-74907
No data.