Executive brief
Grav is an open-source flat-file CMS used to build and manage websites. A vulnerability in its XSS detection function allows an authenticated page editor to bypass the security checks by inserting a single invalid UTF-8 byte into page content, enabling them to inject malicious JavaScript that executes when site visitors view the affected page.
Technical details
The vulnerability exists in Security::detectXss() in system/src/Grav/Common/Security.php. All XSS detection regex patterns use the PCRE /u (UTF-8) modifier; when preg_match() encounters even one invalid UTF-8 byte sequence in the input, it returns false for the entire call instead of attempting to match the pattern. Since detectXss() only checks truthiness of the return value, a single malformed UTF-8 byte silently causes all six XSS checks to fail. An authenticated attacker with page-edit permissions (without security.xss_whitelist privilege) can inject an invalid UTF-8 byte anywhere in the page content alongside malicious JavaScript, bypassing both the save-time Validation::checkSafety() gate and the render-time detectXssInEditorContent() backstop. The browser normalizes the invalid byte to U+FFFD and executes the stored XSS payload normally. A patch is available in version 2.0.14.
Affected products
- Getgrav Grav < 2.0.14
Timeline
- 2026-08-03: disclosed
- 2026-08-18: advisory
- 2026-08-03: patched: Patch available in version 2.0.14