CVE-2026-53654
Grav: Unauthenticated open redirect via login twofa_cancel _redirect
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or protocol-relative Location target. Controller::execute() applies the field when taskTwofa_cancel() sets no redirect, and Grav::getRedirectResponse() accepts the target through Uri::isExternal(), enabling phishing redirects from a trusted Grav host. This issue is fixed in version 3.8.5.
| CWE | CWE-601 |
| Vendor | getgrav |
| Product | grav |
| Published | Aug 19, 2026 |
| Last Updated | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for getgrav grav
Be the first to know when new unknown vulnerabilities affecting getgrav grav are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
getgrav / grav
< 3.8.5