← Terug naar overzicht

Grav CMS versions before 2.0.16 contain a symlink following vulnerability in the Scheduler Job::createLockFile() function. Local attackers can exploit this by pre-creating symlinks at predictable lock file paths within the world-writable temp directory. When a scheduled job runs, it follows the symlink and overwrites the target file with a job ID string. The attacker can point the symlink to any file writable by the web server process, enabling arbitrary file overwrite. This vulnerability requires local access but can have significant impact on system integrity. The issue has been patched in Grav CMS version 2.0.16. Multiple advisories have been published including on GitHub Security Advisories and VulnCheck.

Affected products

  • Grav CMS

Related CVE's

  • CVE-2026-72696

Categories

  • Web Technologies