THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q2j8-x8hf-63ch (medium) — Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

[GHSA] GHSA-q2j8-x8hf-63ch (medium) — Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

medgithub_advisoriesPublished 2026-09-17

GHSA-q2j8-x8hf-63ch Severity: medium CVE: CVE-2026-75834

Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

## Vulnerability Details

**Component**: getgrav/grav core **File**: `system/src/Grav/Common/Security.php` **Function**: `detectXss()` (all six entries in the `$patterns` array use the PCRE `u` modifier), invoked from `G

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q2j8-x8hf-63ch