Junglewise Threat Intelligence

CVE-2026-42612: getgrav Grav stored XSS in detectXss function

CVE-2026-42612 · Severity: high · CVSS 8.5 · Published 2026-05-11

Technologies: Getgrav Grav, Grav, getgrav/grav (Packagist). Vendors: Getgrav, Grav, Packagist.

Executive brief

Grav, a popular flat-file content management system, is vulnerable to a security flaw that allows users with publisher-level access to inject malicious scripts into website content. These scripts are executed in the browsers of other users, including administrators, when they view the affected pages. This could lead to unauthorized actions, theft of login sessions, or full compromise of administrative accounts.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Grav's `detectXss()` function within `system/src/Grav/Common/Security.php`. The root cause is a flawed regular expression used to identify `on*` event handlers; the pattern specifically expects whitespace or quotes around the equals sign (e.g., `onerror=`). By using unquoted attributes (e.g., `<img src=x onerror=alert(1)>`), an attacker with publisher-level privileges can bypass the filter. This allows for the execution of arbitrary JavaScript in the context of any user viewing the content. The vulnerability has been addressed in version 2.0.0-beta.2 by updating the regex to flag any `on*=` attribute regardless of surrounding characters.

Affected products

  • getgrav Grav < 2.0.0-beta.2

Timeline

  • 2026-04-24: patched: Fix applied to Grav core 2.0 branch.
  • 2026-04-27: disclosed: Advisory published by maintainer.
  • 2026-05-05: advisory: GitHub Advisory published.
  • 2026-05-11: other: NVD published.

References

Related threats