THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-269c-h76q-8cxw (medium) — Grav: Stored XSS via quoted-attribute bypass in detectXss

[GHSA] GHSA-269c-h76q-8cxw (medium) — Grav: Stored XSS via quoted-attribute bypass in detectXss

highgithub_advisoriesPublished 2026-09-17

GHSA-269c-h76q-8cxw Severity: medium CVE: CVE-2026-72832

Grav: Stored XSS via quoted-attribute bypass in detectXss

### Summary

A page editor without `admin.super` can place an event handler after a `>` inside a quoted attribute. Grav accepts and stores the page, then executes the handler in the application origin when a visitor opens it.

### Details

`Security::detectXss()` (`system/src/Grav/C

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-269c-h76q-8cxw