Executive brief
Grav, a popular open-source content management system, is vulnerable to a security flaw that allows users with page-editing permissions to embed malicious scripts into website content. These scripts can automatically execute in the browsers of other visitors, including site administrators. This could allow an attacker to hijack administrative sessions, steal sensitive data, or perform unauthorized actions on the website.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Grav's shortcode-core attribute handlers due to insufficient input validation. The 'Security::detectXss()' function only filters for literal angle brackets (<), which are not required for shortcode syntax. An attacker with 'admin.pages' permissions can craft a shortcode with a malicious attribute (e.g., using a double quote to break out of an HTML attribute) that injects event handlers like 'onmouseover'. When the page is rendered, the injected script executes in the context of any viewer's session. This can be used to steal admin nonces and hijack high-privilege sessions. The vulnerability affects versions up to and including 6.2.1.
Affected products
- getgrav Grav <= 6.2.1
Timeline
- 2026-07-07: advisory: GitHub Security Advisory published
- 2026-07-21: disclosed: NVD publication date