THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w3f4-8pj2-599w (high) — Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

[GHSA] GHSA-w3f4-8pj2-599w (high) — Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

highgithub_advisoriesPublished 2026-09-17

GHSA-w3f4-8pj2-599w Severity: high CVE: CVE-2026-69089

Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Reported by: Nihad Huseynli (@nihaddhuseynli (https://github.com/nihaddhuseynli)) — nihadd.huseynli@gmail.com

▎ Note: I attempted to report this via security@getgrav.org first, per SECURITY.md, but the email bounced with 550 5.1.1 Address

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w3f4-8pj2-599w