THREAT OPS › Threat News › [GHSA] GHSA-vfmf-q6x9-cw96 (critical) — Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
[GHSA] GHSA-vfmf-q6x9-cw96 (critical) — Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
GHSA-vfmf-q6x9-cw96 Severity: critical CVE: CVE-2026-75828
Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
## Affected versions and vulnerable location
- Confirmed on grav core at `78ebfc1` (tag 2.0.13). - Detector: `system/src/Grav/Common/Security.php:290`, the `on_events` regex, run via `patternMatches()` (`:315-330
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-75828cve
Original source: https://github.com/advisories/GHSA-vfmf-q6x9-cw96