{"id":"CVE-2026-69089","aliases":["GHSA-w3f4-8pj2-599w"],"url":"https://o3.security/vulnerability/CVE-2026-69089","summary":"Grav CMS before 2.0.11 Path Traversal via watermark","details":"Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\\Toolbox\\ResourceLocator\\UniformResourceLocator::findResource(). Because the file:// scheme branch only lexically collapses '..' segments without a realpath/containment check, an editor authoring Markdown image syntax with traversal sequences can cause arbitrary image files outside Grav's media sandbox to be composited into a carrier image, which is then cached and served from a public, unauthenticated URL — disclosing those files to anonymous visitors.","published":"2026-08-03T13:20:43.593Z","modified":"2026-09-02T03:30:57.662819954Z","cvss":null,"epss":{"score":0.00373,"percentile":0.3056,"asOf":"2026-08-19"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/getgrav/grav/commit/b282200a65ce979377963180629babd2335212ba","label":"getgrav/grav@b282200"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69089.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-w3f4-8pj2-599w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69089"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/grav-cms-before-path-traversal-via-watermark"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/b282200a65ce979377963180629babd2335212ba"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/c569a53304cd7d95ff21bffa6fc590adcf0be83d"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/db8c1fcd63aaaf6d6b244bc6b4cfa5f7b96bbc7f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-02T03:30:57.662819954Z"}}