Medium severity6.5NVD Advisory· Published Aug 19, 2026
CVE-2026-61690
CVE-2026-61690
Description
Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, file-count, or nesting-depth limits. Code using Archiver::create('zip') to extract an attacker-controlled archive can exhaust disk space or inodes and make the site unavailable. This issue is fixed in version 2.0.1.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.