Junglewise Threat Intelligence

CVE-2026-58657: Grav stored CSS injection in Markdown image resize action

CVE-2026-58657 · Severity: medium · CVSS 4.8 · Published 2026-07-08

Technologies: Grav, getgrav/grav (Packagist), Getgrav Grav. Vendors: Grav, Packagist, Getgrav.

Executive brief

Grav is a flat-file CMS that allows users to create and edit page content in Markdown. A lower-privileged content editor can embed specially crafted image URLs in page Markdown that inject arbitrary CSS declarations into the rendered HTML. When a higher-privileged user (reviewer or administrator) views or previews the page, the injected CSS executes in their browser context, enabling UI redress attacks, content manipulation, and phishing overlays without requiring JavaScript.

Technical details

The vulnerability is a CSS injection flaw in the Markdown image processing pipeline. The parsedownElement() method in StaticResizeTrait directly concatenates width and height values into the styleAttributes dictionary without validating that the input is numeric or free of CSS delimiters. When a Markdown image URL contains resize=100;position:fixed;...;200, the parser extracts "100" and "200" as width/height but does not strip the intervening CSS properties. Later, parsedownElement() serializes these attributes as raw CSS declarations ($style .= $key . ': ' . $value . ';'), allowing the injected semicolons and property names to break out of the width/height context and create new CSS rules. An attacker with content-editing privileges can store this payload in a page; when viewed by a higher-privileged user, the injected CSS is rendered in their session. The attack vector is network-based (edit and view a Grav instance) and requires high privilege (editor role) and user interaction (admin/reviewer viewing the page). Prior sanitizers on direct style() and attribute() query parameters are bypassed because resize() writes directly to styleAttributes without passing through the same validation gate.

Affected products

  • Getgrav Grav 2.0.0-rc.9; 2.0 branch

Timeline

  • 2026-06-22: advisory: Advisory published to GitHub Advisory Database
  • 2026-09-16: disclosed: Vulnerability details and timeline published; CVE-2026-58657 assigned
  • 2026-09-16: patched: Patched in version 2.0.0

References

Related threats