
Grav CMS advisory for CVE-2026-42608 lists exactly one fixed version: 2.0.0-beta.2. Everybody runs 1.7. For five months, the remedy on offer to them was a pre-release of a major upgrade. 🧷 Unauthenticated path traversal in the FormFlash component, through the `__form-flash-id` parameter. 8.8 under CVSS v4.0, with exploit maturity recorded in the vector as proof of concept. Affected range 0.8.0 through 2.0.0-beta.1. Advisory published 27 April 2026. Machine-readable record on 5 May. ⚖️ On 18 September, 144 days later, the Clop ransomware group's leak site was defaced. It was running Grav 1.7.43. Grav shipped 1.7.53.4 with the backport the following day. The backport existed. It just had not been released, and nothing in the advisory said one was coming. 🧮 1.7.43 also predates 1.7.45, which fixed a separate path traversal, CVE-2024-27921, in March 2024. So the leak site was behind on two. ShinyHunters claimed source code, plugins, server logs and the Tor onion private keys. 🔍 What this does not establish: not which flaw was used, because nobody has said. Not that the maintainers did anything improper, because listing the branch you fixed is honest. 🔑 The practical point is about how you read a fixed-version field. A range that ends in a beta is not a patch instruction for a production branch. It is a statement about a different branch, and the difference is five months wide. Full briefing: https://www.pk-sharma.com/briefing/the-only-fix-was-a-beta #InfoSec #CyberSecurity #Vulnerability #PatchManagement #CVE #ThreatIntel #AppSec #Ransomware #CISO #RiskManagement #BlueTeam #SecOps #OpenSource #UKTech
