CVE-2026-74907: Grav before 2.0.15 contains a path traversal vulnerability in the static asset server with
HIGHHigh-risk vulnerability — CVSS 5.9
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling directories by exploiting directory names that extend the base path string, such as requesting assets-secret when assets is the configured base.
CVE · detail
- CVE-2026-74907nvd ↗EPSS 0.33%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected