THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2vcx-h8p2-9pg9 (medium) — Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()

[GHSA] GHSA-2vcx-h8p2-9pg9 (medium) — Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()

highgithub_advisoriesPublished 2026-09-16

GHSA-2vcx-h8p2-9pg9 Severity: medium CVE: CVE-2026-59193

Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()

### Summary An authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool. The method `Installer::unZip()` calls `ZipArchive::extractTo()` without any limit on uncompressed size, entr

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2vcx-h8p2-9pg9