THREAT OPS › Threat News › [GHSA] GHSA-w3f4-8pj2-599w (high) — Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
[GHSA] GHSA-w3f4-8pj2-599w (high) — Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
GHSA-w3f4-8pj2-599w Severity: high CVE: CVE-2026-69089
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
Reported by: Nihad Huseynli (@nihaddhuseynli (https://github.com/nihaddhuseynli)) — nihadd.huseynli@gmail.com
▎ Note: I attempted to report this via security@getgrav.org first, per SECURITY.md, but the email bounced with 550 5.1.1 Address
Indicators of compromise
- db8c1fcd63aaaf6d6b244bc6b4cfa5f7b96bbc7fsha1
- c569a53304cd7d95ff21bffa6fc590adcf0be83dsha1
- b282200a65ce979377963180629babd2335212basha1
- CVE-2026-69089cve
- nihadd.huseynli@gmail.comemail
- security@getgrav.orgemail
Original source: https://github.com/advisories/GHSA-w3f4-8pj2-599w