Executive brief
The Grav Admin2 plugin, used for managing the Grav content management system, contains a flaw that publicly reveals sensitive configuration details. An unauthorized visitor can see the exact version of the software being used, the internal API structure, and the server's environment type. This information acts as a roadmap for attackers, allowing them to identify and launch specific attacks against the system without needing to guess how it is configured.
Technical details
The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before version 2.0.4 embeds a global JavaScript variable, 'window.__GRAV_CONFIG__', within the Admin2 SPA bootstrap page. This object is included in every unauthenticated response at the /grav/admin route and its subroutes. The exposed data includes the server URL, API prefix, admin base path, runtime environment type, and exact version numbers for both Grav and the Admin2 plugin. This information disclosure (CWE-200) allows a remote, unauthenticated attacker to perform precise fingerprinting and select version-specific exploits without traditional reconnaissance. The issue is resolved in version 2.0.4.
Affected products
- getgrav Grav Admin2 plugin < 2.0.4
Timeline
- 2026-06-24: advisory: Vendor advisory published via GitHub
- 2026-07-11: disclosed: NVD publication date