Medium severity4.8GHSA Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-55890
CVE-2026-55890
Description
Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media attribute action (CVE-2026-42841) leaves the sibling MediaObjectTrait::style method reachable through the same Markdown excerpt-action pipeline, allowing an editor to save Markdown image style parameters that are written into the rendered img style attribute without sanitization. This issue is fixed in version 2.0.0-rc.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | < 2.0.0-rc.9 | 2.0.0-rc.9 |
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.