Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026
Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__
CVE-2026-61454
Description
The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime environment type, and exact Grav and Admin2 version numbers, allowing an unauthenticated attacker to fingerprint the deployment and select version-specific exploits without reconnaissance.
Affected products
2- Range: <2.0.4
Patches
Vulnerability mechanics
References
2- github.com/getgrav/grav/security/advisories/GHSA-pfjq-chp8-3vghmitrevendor-advisory
- www.vulncheck.com/advisories/grav-before-information-disclosure-via-grav-configmitrethird-party-advisory
News mentions
0No linked articles in our index yet.