Executive brief
Grav is a flat-file content management system used to build websites. This vulnerability allows a page editor (without full admin privileges) to inject malicious JavaScript code into page content that executes when any visitor views the page, potentially stealing session tokens or sensitive information. The flaw bypasses Grav's XSS detection by embedding an event handler inside a quoted HTML attribute.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the Security::detectXss() function (system/src/Grav/Common/Security.php). The detector uses a regex pattern `[^>]*?` anchored at `<` which cannot cross the first literal `>` character; when a `>` appears inside a quoted attribute value, the browser's HTML parser keeps the tag open and parses subsequent event handlers (e.g., onerror), causing a disagreement between the detector and the browser. An attacker with page-editing privileges but without admin.super can save malicious content like `<img src=x title=">" onerror=alert(document.domain)>`, which is accepted by the flawed detector but executed by browsers. This affects Grav versions 1.5.2 through 2.0.12 and is fixed in 2.0.13. The attack requires editing privileges but no admin.super role, and impacts all site visitors including unauthenticated users.
Affected products
- Grav Grav 1.5.2 through 2.0.12
Timeline
- 2026-07-26: disclosed
- 2026-08-14: patched: Fixed in version 2.0.13