A high-severity path traversal flaw tracked as CVE-2026-69089 affects Grav CMS before version 2.0.11, with exploitation confirmed in 2.0.10. The bug resides in ImageMedium::watermark(), where an unsanitized $image argument is passed to RocketTheme\Toolbox\ResourceLocator\UniformResourceLocator::findResource(). Because file:// path handling only collapses .. segments lexically and does not enforce a realpath or containment check, attackers can traverse outside Grav's intended media sandbox.
An editor able to author Markdown image syntax can abuse the watermark feature to reference arbitrary image files on the server, causing those files to be composited into another image. Grav then caches and serves the resulting image from a public unauthenticated URL, enabling anonymous information disclosure. The issue is classified as CWE-22 with a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, and Grav CMS 2.0.11 is reported as unaffected.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A new CVE record for CVE-2026-69089 was received by disclosure@vulncheck.com. The record describes the Grav CMS path traversal issue and references related GitHub advisories and commits.
A path traversal vulnerability was identified in Grav CMS, confirmed in version 2.0.10 and affecting versions earlier than 2.0.11. The flaw is in ImageMedium::watermark(), where an unsanitized image argument can traverse outside the media sandbox and expose arbitrary image files via a cached public URL.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.