๐Ÿ” CVE Alert

CVE-2026-86197

UNKNOWN 0.0

Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed for all visitors including administrators.

CWE CWE-79
Vendor getgrav
Product grav
Published Sep 5, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for getgrav grav

Be the first to know when new unknown vulnerabilities affecting getgrav grav are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

getgrav / grav
0 < 2.0.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/getgrav/grav/security/advisories/GHSA-8hgv-xc77-jmcr vulncheck.com: https://www.vulncheck.com/advisories/grav-before-2.0.20-cross-site-scripting-via-assets-sandbox

Credits

๐Ÿ” skeletonsec