THREAT OPS › Threat News › [GHSA] GHSA-q2j8-x8hf-63ch (medium) — Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
[GHSA] GHSA-q2j8-x8hf-63ch (medium) — Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
GHSA-q2j8-x8hf-63ch Severity: medium CVE: CVE-2026-75834
Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
## Vulnerability Details
**Component**: getgrav/grav core **File**: `system/src/Grav/Common/Security.php` **Function**: `detectXss()` (all six entries in the `$patterns` array use the PCRE `u` modifier), invoked from `G
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-75834cve
Original source: https://github.com/advisories/GHSA-q2j8-x8hf-63ch