Threat Advisory

Twig XSS Bypass Allows Stored Attacks on All Visitors

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Grav CMS is affected by three security vulnerabilities involving decompression handling, XSS validation, and CSS injection. The vulnerabilities affect Grav 1.x and 2.0 releases and can result in denial of service, sensitive-session attacks, UI manipulation, and stored cross-site scripting depending on the affected configuration and user privileges.

CVE-2026-59193 (CVSS 6.9 v4 / 4.9 v3 – Medium): A zip-bomb and resource-exhaustion vulnerability in Grav's Installer::unZip(). An authenticated admin.super user can upload a specially crafted ZIP archive containing highly compressed data, numerous files, or deeply nested directories. Because the installer does not enforce limits on uncompressed size, entry count, or directory depth, exploitation can exhaust disk space/inodes, trigger stack overflow during cleanup, and cause denial of service. Affected versions are Grav >=1.0.0 and <2.0.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Grav CMS is affected by three security vulnerabilities involving decompression handling, XSS validation, and CSS injection. The vulnerabilities affect Grav 1.x and 2.0 releases and can result in denial of service, sensitive-session attacks, UI manipulation, and stored cross-site scripting depending on the affected configuration and user privileges.

CVE-2026-59193 (CVSS 6.9 v4 / 4.9 v3 – Medium): A zip-bomb and resource-exhaustion vulnerability in Grav's Installer::unZip(). An authenticated admin.super user can upload a specially crafted ZIP archive containing highly compressed data, numerous files, or deeply nested directories. Because the installer does not enforce limits on uncompressed size, entry count, or directory depth, exploitation can exhaust disk space/inodes, trigger stack overflow during cleanup, and cause denial of service. Affected versions are Grav >=1.0.0 and <2.0.0.[emaillocker id="1283"]

CVE-2026-61453 (CVSS 5.1 v4 – Medium): A stored XSS vulnerability caused by a Twig string-concatenation validation bypass. The XSS validator checks page content before Twig processing, allowing attackers to dynamically construct dangerous event handlers, HTML tags, or protocols after validation. With Twig content processing enabled and page-write permission, an attacker can inject persistent JavaScript that executes for visitors, potentially enabling session-cookie theft, unauthorized actions, or website defacement. Grav 2.0.0 is affected.

CVE-2026-58657 (CVSS 4.8 v3 – Medium): A stored CSS injection vulnerability in Grav's Markdown image resize() functionality. A lower-privileged content editor can manipulate image resize parameters to inject additional CSS declarations into the generated style attribute. This can create UI overlays and manipulate content displayed to higher-privileged reviewers or administrators. The issue affects Grav 2.0.0-rc.9 and the specified 2.0 branch.

RECOMMENDATION:

We recommend you to update Grav to version 2.0.1 or 2.0.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu