CVE-2026-7317: Grav CMS Cache Value FileCache.php doGet deserialization
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made public and could be used. Upgrading to version 2.0.0-beta.2 addresses this issue. The patch is identified as c66dfeb5f. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Grav CMSto a version that resolves this vulnerability.Fixed in 2.0.0-beta.2Patch c66dfeb5f
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7317?
CVE-2026-7317 is classified as a medium-severity vulnerability.
How do I fix CVE-2026-7317?
To fix CVE-2026-7317, update Grav CMS to a version later than 1.7.49.5 or 2.0.0-beta.1.
What components are affected by CVE-2026-7317?
CVE-2026-7317 affects the FileCache::doGet function in Grav CMS's Cache Value Handler.
Is CVE-2026-7317 a remote exploitation risk?
Yes, CVE-2026-7317 can allow for remote code execution through deserialization.
Which versions of Grav CMS are vulnerable to CVE-2026-7317?
Grav CMS versions up to 1.7.49.5 and 2.0.0-beta.1 are vulnerable to CVE-2026-7317.