<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 08:56:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-358873</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358873</link>
      <description>EUVD-2026-358873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358873</guid>
    </item>
    <item>
      <title>fkie_cve-2026-72695</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72695</link>
      <description>&lt;p&gt;Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the basename portion of the filename while preserving unvalidated directory paths containing ../ sequences that are passed to unlink(), enabling deletion of files outside the intended media storage directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the basename portion of the filename while preserving unvalidated directory paths containing ../ sequences that are passed to unlink(), enabling deletion of files outside the intended media storage directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-72695</guid>
    </item>
    <item>
      <title>GHSA-jq29-c7v8-rg55 — Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jq29-c7v8-rg55</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;# Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A path traversal vulnerability in `MediaUploadTrait::deleteFile()` allows an authenticated user with media management permissions to delete arbitrary files on the server. The method validates only the basename portion of the filename using `Utils::checkFilename()`, while the directory path (which may contain `../` sequences) is preserved and passed unvalidated to `unlink()`. This enables directory escape from the intended media storage path.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**High (8.1)** - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H&lt;/p&gt;
&lt;p&gt;## CWE&lt;/p&gt;
&lt;p&gt;CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `system/src/Grav/Common/Media/Traits/MediaUploadTrait.php`, the `deleteFile()` method (lines 332-365) performs filename validation only on the basename, not the full path:&lt;/p&gt;
&lt;p&gt;```php
public function deleteFile(string $filename, ?array $settings = null): void
{
    $settings = $this-&amp;gt;getUploadSettings($settings);
    $filesystem = Filesystem::getInstance(false);&lt;/p&gt;
&lt;p&gt;// Line 339-340: Only the BASENAME is validated
    $basename = $filesystem-&amp;gt;basename($filename);  // e.g. &amp;#34;evil.jpg&amp;#34; from &amp;#34;../../evil.jpg&amp;#34;
    if (!Utils::checkFilename($basename)) {         // passes - no traversal in basename
        throw new RuntimeException(/* ... */);
    }&lt;/p&gt;
&lt;p&gt;$path = $settings[&amp;#39;destination&amp;#39;] ?? $this-&amp;gt;getPath();
    // ...&lt;/p&gt;
&lt;p&gt;// Line 353: Full pathname (with traversal) is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;# Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A path traversal vulnerability in `MediaUploadTrait::deleteFile()` allows an authenticated user with media management permissions to delete arbitrary files on the server. The method validates only the basename portion of the filename using `Utils::checkFilename()`, while the directory path (which may contain `../` sequences) is preserved and passed unvalidated to `unlink()`. This enables directory escape from the intended media storage path.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**High (8.1)** - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H&lt;/p&gt;
&lt;p&gt;## CWE&lt;/p&gt;
&lt;p&gt;CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;)&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `system/src/Grav/Common/Media/Traits/MediaUploadTrait.php`, the `deleteFile()` method (lines 332-365) performs filename validation only on the basename, not the full path:&lt;/p&gt;
&lt;p&gt;```php
public function deleteFile(string $filename, ?array $settings = null): void
{
    $settings = $this-&amp;gt;getUploadSettings($settings);
    $filesystem = Filesystem::getInstance(false);&lt;/p&gt;
&lt;p&gt;// Line 339-340: Only the BASENAME is validated
    $basename = $filesystem-&amp;gt;basename($filename);  // e.g. &amp;#34;evil.jpg&amp;#34; from &amp;#34;../../evil.jpg&amp;#34;
    if (!Utils::checkFilename($basename)) {         // passes - no traversal in basename
        throw new RuntimeException(/* ... */);
    }&lt;/p&gt;
&lt;p&gt;$path = $settings[&amp;#39;destination&amp;#39;] ?? $this-&amp;gt;getPath();
    // ...&lt;/p&gt;
&lt;p&gt;// Line 353: Full pathname (with traversal) is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jq29-c7v8-rg55</guid>
    </item>
  </channel>
</rss>
