High severity8.1NVD Advisory· Published Jul 17, 2026· Updated Jul 23, 2026
CVE-2026-62234
CVE-2026-62234
Description
Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.