Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

CVE-2026-62234: Grav Webhooks Allow Local File Access

CVE-2026-62234 · published 2 months ago
Summary

Grav webhooks before version 2.0.4 allow authorized users to access local files and potentially sensitive information. This can happen when a malicious user creates a webhook with a specific type of URL. To fix this issue, update Grav to version 2.0.4 or later.

What to do
  • Update getgrav grav to version 2.0.4 or later.
Affected software
VendorProductAffected versions
getgrav grav < 2.0.4
getgrav grav-plugin-api < 1.0.6
Original advisory text
Grav < 2.0.4 SSRF via Unrestricted cURL Protocols
Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers.
Severity
7.8 High
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published17 Jul 2026
Updated27 Sep 2026
First seen17 Jul 2026
Sources
CVE-2026-62234 · MITRE
Track software like this
Free during beta