Executive brief
Grav CMS is a flat-file content management system used to build and manage websites. A vulnerability in its image watermarking feature allows an editor to craft malicious Markdown syntax that discloses arbitrary image files from the server's disk by compositing them into cached, publicly-accessible images—exposing sensitive files to any anonymous visitor without authentication.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in the ImageMedium::watermark() method, which processes the $image parameter without proper sanitization before passing it to UniformResourceLocator::findResource(). The underlying ResourceLocator only performs lexical collapse of ".." path segments using string manipulation, without realpath() validation or containment checks. An authenticated editor can author Markdown image syntax with traversal sequences (e.g., "../../../etc/passwd.png") that resolve to arbitrary absolute filesystem paths. If a valid image file exists at that path, its pixel content is composited into a carrier image, cached, and served from a public unauthenticated URL, effectively disclosing the file to anonymous users. The attack requires editor privileges to author Markdown, but the disclosure impacts all anonymous visitors. A patch was released in Grav 2.0.11.
Affected products
- Grav Grav CMS 2.0.10
Timeline
- 2026-07-21: disclosed
- 2026-07-21: patched: Patched in version 2.0.11