Vulnerability Description
Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth. This issue is fixed in version 2.0.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getgrav | Grav | >= 1.0.0, < 2.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/getgrav/grav/commit/23d6f2adf4ce11889c088ac8557c8314baeef781Patch
- https://github.com/getgrav/grav/releases/tag/2.0.0Product
- https://github.com/getgrav/grav/security/advisories/GHSA-2vcx-h8p2-9pg9ExploitVendor Advisory
- https://github.com/getgrav/grav/security/advisories/GHSA-2vcx-h8p2-9pg9ExploitVendor Advisory
FAQ
What is CVE-2026-59193?
CVE-2026-59193 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool becaus...
How severe is CVE-2026-59193?
CVE-2026-59193 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59193?
Check the references section above for vendor advisories and patch information. Affected products include: Getgrav Grav.