Path traversal in Grav CMS - CVE-2025-66295

 

Path traversal in Grav CMS - CVE-2025-66295

Published: May 5, 2026


Vulnerability identifier: #VU130054
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66295
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to overwrite arbitrary YAML files and modify other user accounts.

The vulnerability exists due to path traversal in the Admin UI user creation functionality when processing a username containing path traversal sequences during new user creation. A remote user can create a new user with a specially crafted username to overwrite arbitrary YAML files and modify other user accounts.

Exploitation requires the ability to create users through the Admin UI.


Affected software

Grav CMS

How to mitigate CVE-2025-66295

Install security update from vendor's website.

Grav CMS - update to 1.8.0 beta.27

External References

Related Security Bulletins