THREAT OPS › Threat News › [GHSA] GHSA-269c-h76q-8cxw (medium) — Grav: Stored XSS via quoted-attribute bypass in detectXss
[GHSA] GHSA-269c-h76q-8cxw (medium) — Grav: Stored XSS via quoted-attribute bypass in detectXss
GHSA-269c-h76q-8cxw Severity: medium CVE: CVE-2026-72832
Grav: Stored XSS via quoted-attribute bypass in detectXss
### Summary
A page editor without `admin.super` can place an event handler after a `>` inside a quoted attribute. Grav accepts and stores the page, then executes the handler in the application origin when a visitor opens it.
### Details
`Security::detectXss()` (`system/src/Grav/C
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- ad9709f865b09b68798fb1ac375b484a8cc1d892sha1
- CVE-2026-72832cve
Original source: https://github.com/advisories/GHSA-269c-h76q-8cxw