CVE-2024-27921(getgrav / grav)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .json, .zip, .css, .gif, etc. This critical security flaw poses severe risks, that can allow attackers to inject arbitrary code on the server, undermine integrity of backup files by overwriting existing files or creating new ones, and exfiltrate sensitive data using CSS exfiltration techniques. Upgrading to patched version 1.7.45 can mitigate the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grav

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
grav

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-26: 109-26
Referenced assets1 URL
By indicator
Full discourse1 post
  • P.K. Sharma@_pksharma

    Grav CMS advisory for CVE-2026-42608 lists exactly one fixed version: 2.0.0-beta.2. Everybody runs 1.7. For five months, the remedy on offer to them was a pre-release of a major upgrade. 🧷 Unauthenticated path traversal in the FormFlash component, through the `__form-flash-id` parameter. 8.8 under CVSS v4.0, with exploit maturity recorded in the vector as proof of concept. Affected range 0.8.0 through 2.0.0-beta.1. Advisory published 27 April 2026. Machine-readable record on 5 May. ⚖️ On 18 September, 144 days later, the Clop ransomware group's leak site was defaced. It was running Grav 1.7.43. Grav shipped 1.7.53.4 with the backport the following day. The backport existed. It just had not been released, and nothing in the advisory said one was coming. 🧮 1.7.43 also predates 1.7.45, which fixed a separate path traversal, CVE-2024-27921, in March 2024. So the leak site was behind on two. ShinyHunters claimed source code, plugins, server logs and the Tor onion private keys. 🔍 What this does not establish: not which flaw was used, because nobody has said. Not that the maintainers did anything improper, because listing the branch you fixed is honest. 🔑 The practical point is about how you read a fixed-version field. A range that ends in a beta is not a patch instruction for a production branch. It is a statement about a different branch, and the difference is five months wide. Full briefing: https://www.pk-sharma.com/briefing/the-only-fix-was-a-beta #InfoSec #CyberSecurity #Vulnerability #PatchManagement #CVE #ThreatIntel #AppSec #Ransomware #CISO #RiskManagement #BlueTeam #SecOps #OpenSource #UKTech

    00000113
    183 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetgravgrav---

Explore more