What is CVE-2026-61690?
Grav, a file-based web platform, has a Zip Slip vulnerability in `ZipArchiver::extract()` due to missing enforcement of `archive` limits, potentially allowing unauthenticated remote code execution (RCE). Users should immediately upgrade to version 2.0.1 or later.
Azərbaycanca: Grav fayl əsaslı veb platformasında `ZipArchiver::extract()` funksiyasında `archive` limitləri tətbiq edilmədiyi üçün Zip Slip zəifliyi mövcuddur. Bu, autentifikasiyasız uzaqdan kod icrasına (RCE) səbəb ola bilər. İstifadəçilər dərhal 2.0.1 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Grav
FAQ2
Is unauthenticated remote code execution possible through the Zip Slip vulnerability in the Grav platform?
Yes, CVE-2026-61690 can potentially allow unauthenticated remote code execution (RCE) due to missing enforcement of `archive` limits in the `ZipArchiver::extract()` function.
To which version should the Grav platform be upgraded to mitigate CVE-2026-61690?
To protect against CVE-2026-61690, users should immediately upgrade to Grav version 2.0.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.