VYPR
Medium severity4.9NVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026

CVE-2026-59193

CVE-2026-59193

Description

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth. This issue is fixed in version 2.0.0.

Affected products

4
  • ghsa-coords
    Range: >= 1.0.0, < 2.0.0
  • Grav CMS/Gravllm-fuzzy
    Range: <2.0.0
  • Getgrav/Grav2 versions
    cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*range: >=1.0.0,<2.0.0
    • cpe:2.3:a:getgrav:grav:2.0.0:beta1:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.