THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jq29-c7v8-rg55 (high) — Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

[GHSA] GHSA-jq29-c7v8-rg55 (high) — Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

medgithub_advisoriesPublished 2026-09-17

GHSA-jq29-c7v8-rg55 Severity: high CVE: CVE-2026-72695

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

# Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

## Summary

A path traversal vulnerability in `MediaUploadTrait::deleteFile()` allows an authenticated user with media management permissions to delete arbitrary files on the

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jq29-c7v8-rg55