What is CVE-2026-61607?
CVE-2026-61607 impacts the Grav API Plugin for Grav CMS. Prior to version 1.0.2, the SVG upload pipeline in `HandlesMediaUploads::processUploadedFile()` fails to call `Security::sanitizeSVG()`, allowing malicious SVG files to be uploaded. Users should immediately upgrade the plugin to version 1.0.2 or later.
Azərbaycanca: CVE-2026-61607 Grav CMS-in API Pluginində aşkarlanmışdır. 1.0.2 versiyasından əvvəlki versiyalarda SVG fayl yükləmə zamanı `Security::sanitizeSVG()` funksiyası çağırılmadığı üçün təhlükəli SVG fayllarının yüklənməsinə imkan verir. İstifadəçilər dərhal plugin-i 1.0.2 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-434
FAQ1
In which component was CVE-2026-61607 found and how can it be mitigated?
The vulnerability was found in the Grav API Plugin for Grav CMS, in versions prior to 1.0.2. To mitigate it, the plugin should be immediately upgraded to version 1.0.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.