Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rv94-vqvr-wjjh

Опубликовано: 17 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.4
CVSS3: 8.1

Описание

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers.

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers.

EPSS

Процентиль: 22%
0.00297
Низкий

8.4 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.1
nvd
29 дней назад

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers.

EPSS

Процентиль: 22%
0.00297
Низкий

8.4 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-918