Path traversal in Grav CMS - CVE-2025-66302
Published: May 5, 2026
Grav CMS
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in the backup tool when processing user-supplied backup root folder paths. A remote privileged user can supply a crafted path to disclose sensitive information.
The impact depends on the privileges of the account running the application.