Grav CMS path traversal (CVE-2026-42608)
Vulnerability
Summary
Hide ▲
Show ▼
Grav CMS 1.7.x installations were exposed to CVE-2026-42608, an unauthenticated path traversal flaw in form upload handling that could create unsafe upload paths and write files outside the intended directory. Grav said the bug was fixed in Grav 2.0 (2.0.0-beta.2) earlier this year and later backported as Grav 1.7.53.4. The weakness was used against a server running Grav CMS 1.7.43.
Related Happenings
Clop leak site hit by network compromise linked to ShinyHunters
Incident
H score31
First: 25.09.2026 23:57
Last: 25.09.2026 23:57
Sources 1
How related:
The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.
About this happening:
The Clop leak site was breached and defaced by ShinyHunters, forcing the operation to shift to a new Tor address. The compromise was tied to Grav CMS 1.7.43 an...
Clop leak site hit by network compromise linked to ShinyHunters
IncidentHow related: The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.
About this happening: The Clop leak site was breached and defaced by ShinyHunters, forcing the operation to shift to a new Tor address. The compromise was tied to Grav CMS 1.7.43 an...
Timeline
-
25.09.2026 23:57 2 articles · 0h ago
Grav publishes CVE-2026-42608 advisory and fixes the path traversal flaw in Grav 2.0
Technical Analysis UpdateGrav identified CVE-2026-42608 as a path traversal vulnerability, said it was privately reported and fixed in Grav 2.0 (2.0.0-beta.2), and published the advisory on April 27.
Show sources
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw — www.bleepingcomputer.com — 25.09.2026 23:57
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw — www.bleepingcomputer.com — 25.09.2026 23:57
-
25.09.2026 03:00 1 articles · 21h ago
Grav backports the CVE-2026-42608 fix to Grav 1.7.53.4
Mitigation Patch UpdateAfter exploitation details were shared, Grav backported the CVE-2026-42608 fix to the 1.7 branch and released Grav 1.7.53.4 yesterday, closing the gap that left older 1.7 installations exposed.
Show sources
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw — www.bleepingcomputer.com — 25.09.2026 23:57
-
25.09.2026 03:00 1 articles · 21h ago
ShinyHunters defaces Clop's Tor leak site through the Grav CMS path traversal flaw
Initial DisclosureShinyHunters breached Clop's Tor leak site after exploiting an unpatched Grav CMS flaw on a server Clop said was running Grav CMS 1.7.43, first uploading a small text file and then replacing the site with a full-page defacement; Clop later moved the leak site to a new Tor address, and ShinyHunters claimed it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop's Tor onion service.
Show sources
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw — www.bleepingcomputer.com — 25.09.2026 23:57