A AegiFlow
MEDIUMCVSS 5.1

GHSA-q8cg-5m48-5c25

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media URL

Published
2026-08-18
Modified
2026-09-17
Sources
github-advisory

Summary

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6qw9-4vv5-jr97. This link is maintained to preserve external references. ### Original Description Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML and JavaScript that executes in viewers' sessions.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistgetgrav/grav

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.