Find notable cyber news and cases, enriched with sources, timelines, and signals.

Grav CMS path traversal (CVE-2026-42608)

Vulnerability
First reported
Last updated
Happening score
H score 8
1 unique sources, 1 articles

Summary

Hide ▲

Grav CMS 1.7.x installations were exposed to CVE-2026-42608, an unauthenticated path traversal flaw in form upload handling that could create unsafe upload paths and write files outside the intended directory. Grav said the bug was fixed in Grav 2.0 (2.0.0-beta.2) earlier this year and later backported as Grav 1.7.53.4. The weakness was used against a server running Grav CMS 1.7.43.

Related Happenings

Clop leak site hit by network compromise linked to ShinyHunters

Incident
H score31 First: 25.09.2026 23:57 Last: 25.09.2026 23:57 Sources 1

How related: The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.

About this happening: The Clop leak site was breached and defaced by ShinyHunters, forcing the operation to shift to a new Tor address. The compromise was tied to Grav CMS 1.7.43 an...

Timeline

  1. 25.09.2026 23:57 2 articles · 0h ago

    Grav publishes CVE-2026-42608 advisory and fixes the path traversal flaw in Grav 2.0

    Technical Analysis Update

    Grav identified CVE-2026-42608 as a path traversal vulnerability, said it was privately reported and fixed in Grav 2.0 (2.0.0-beta.2), and published the advisory on April 27.

    Show sources
  2. 25.09.2026 03:00 1 articles · 21h ago

    Grav backports the CVE-2026-42608 fix to Grav 1.7.53.4

    Mitigation Patch Update

    After exploitation details were shared, Grav backported the CVE-2026-42608 fix to the 1.7 branch and released Grav 1.7.53.4 yesterday, closing the gap that left older 1.7 installations exposed.

    Show sources
  3. 25.09.2026 03:00 1 articles · 21h ago

    ShinyHunters defaces Clop's Tor leak site through the Grav CMS path traversal flaw

    Initial Disclosure

    ShinyHunters breached Clop's Tor leak site after exploiting an unpatched Grav CMS flaw on a server Clop said was running Grav CMS 1.7.43, first uploading a small text file and then replacing the site with a full-page defacement; Clop later moved the leak site to a new Tor address, and ShinyHunters claimed it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop's Tor onion service.

    Show sources