Junglewise Threat Intelligence

CVE-2026-62234: Grav SSRF via unrestricted cURL protocols in webhooks

CVE-2026-62234 · Severity: high · CVSS 8.1 · Published 2026-07-17

Technologies: Grav, Getgrav Grav. Vendors: Grav, Getgrav.

Executive brief

Grav, a popular open-source content management system, contains a security flaw in its webhook system. An authorized user with permission to manage webhooks can trick the server into accessing sensitive local files or internal network services that are not normally exposed to the internet. This could lead to the theft of system passwords, configuration files, or the disruption of internal databases.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Grav's webhook dispatch mechanism due to insufficient protocol validation. While the application uses FILTER_VALIDATE_URL, it fails to restrict the allowed schemes, and the underlying cURL implementation does not use CURLOPT_PROTOCOLS to limit requests to HTTP/HTTPS. An authenticated attacker with 'api.webhooks.write' permissions can register webhooks using file://, dict://, or gopher:// protocols. By triggering a webhook event (such as updating a page), the attacker can read local system files (e.g., /etc/passwd), leak process information from /proc, or interact with internal services like Redis. The issue is resolved in version 2.0.4.

Affected products

  • getgrav Grav < 2.0.4

Timeline

  • 2026-06-29: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: NVD publication date

References

Related threats