VYPR
Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026

Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()

CVE-2026-59193

Description

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth. This issue is fixed in version 2.0.0.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.