Medium severity6.5NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-72697
CVE-2026-72697
Description
Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page authoring privileges can supply arbitrary filesystem paths to media_directory() and use the allow-listed filepath accessor on Medium objects to read file contents of any file matching configured media extensions that the web server process can access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | < 2.0.16 | 2.0.16 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Grav CMS: Eight Vulnerabilities Including Path Traversal and Auth Bypass Disclosed TogetherVypr Intelligence · Aug 25, 2026