CVE-2026-61873: Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path traversal sequences that are processed through Twig templates, allowing them to write arbitrary files including PHP webshells to the web root or other sensitive directories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61873?
The severity of CVE-2026-61873 is rated high with a score of 8.1.
How do I fix CVE-2026-61873?
To fix CVE-2026-61873, upgrade Grav to version 9.1.8 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-61873?
CVE-2026-61873 is an arbitrary file write vulnerability due to improper validation of filename parameters.
What can attackers do with CVE-2026-61873?
Attackers can exploit CVE-2026-61873 to write arbitrary files on the server by submitting specially crafted form data.
Which software is affected by CVE-2026-61873?
CVE-2026-61873 affects Grav versions before 9.1.8.