PT-2025-48551 · Grav · Grav

Published

2025-12-01

·

Updated

2025-12-04

·

CVE-2025-66295

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.8.0-beta.27
Description Grav is a file-based Web platform. A user with user creation privileges can create a new user through the Admin UI and, by supplying a username containing path traversal sequences (for example ../Nijat or ..Nijat), cause Grav to write the account YAML file to an unintended path outside the user/accounts/ directory. The written YAML file can contain account fields such as email, fullname, twofa secret, and hashed password.
Recommendations Update to version 1.8.0-beta.27 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-66295
GHSA-H756-WH59-HHJV

Affected Products

Grav