Path traversal in Grav CMS - CVE-2025-66295
Published: May 5, 2026
Grav CMS
Detailed vulnerability description
The vulnerability allows a remote user to overwrite arbitrary YAML files and modify other user accounts.
The vulnerability exists due to path traversal in the Admin UI user creation functionality when processing a username containing path traversal sequences during new user creation. A remote user can create a new user with a specially crafted username to overwrite arbitrary YAML files and modify other user accounts.
Exploitation requires the ability to create users through the Admin UI.