Junglewise Threat Intelligence

CVE-2026-42841: getgrav Grav stored XSS via Markdown media attribute action

CVE-2026-42841 · Severity: medium · CVSS 4.8 · Published 2026-05-11

Technologies: Getgrav Grav, Grav, getgrav/grav (Packagist). Vendors: Getgrav, Grav, Packagist.

Executive brief

Grav is a web platform used for building and managing websites. A security flaw allows users with page-editing permissions to embed malicious scripts into images using special Markdown syntax. When other users, including administrators, view these pages, the scripts execute in their browsers, potentially leading to unauthorized actions or data theft.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Grav CMS due to improper neutralization of input in the Markdown media action syntax. The application converts Markdown image query parameters into callable media actions via 'call_user_func_array'. An attacker with page-editing privileges can invoke the 'attribute()' method to inject arbitrary HTML attributes, such as 'onload', into the final rendered '<img>' tag. Because the malicious payload is stored as Markdown rather than raw HTML, it bypasses the Admin Plugin's save-time XSS filters. The vulnerability is fixed in version 2.0.0-beta.2 by implementing a strict identifier regex and denylist for attribute names.

Affected products

  • getgrav Grav < 2.0.0-beta.2

Timeline

  • 2026-04-23: patched: Fix committed to repository
  • 2026-04-27: advisory: GitHub Security Advisory published
  • 2026-05-11: disclosed: CVE published to NVD

References

Related threats