A AegiFlow
HIGHCVSS 7.1EPSS 0.3%

CVE-2026-72697

CVE-2026-72697 updated by NVD

Published
2026-09-17
Modified
2026-09-17
EPSS percentile
24%
Sources
github-advisory, nvd

Summary

Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page authoring privileges can supply arbitrary filesystem paths to media_directory() and use the allow-listed filepath accessor on Medium objects to read file contents of any file matching configured media extensions that the web server process can access.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistgetgrav/grav2.0.16

Remediation: Upgrade to 2.0.16 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.