<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 06:44:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-307814</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307814</link>
      <description>EUVD-2026-307814</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307814</guid>
    </item>
    <item>
      <title>fkie_cve-2026-7317</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-7317</link>
      <description>&lt;p&gt;A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made public and could be used. Upgrading to version 2.0.0-beta.2 addresses this issue. The patch is identified as c66dfeb5f. The affected component should be upgraded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made public and could be used. Upgrading to version 2.0.0-beta.2 addresses this issue. The patch is identified as c66dfeb5f. The affected component should be upgraded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-7317</guid>
    </item>
    <item>
      <title>GHSA-gwfr-jfjf-92vv — Grav has Insecure Deserialization in File Cache</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gwfr-jfjf-92vv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;# Insecure Deserialization in File Cache&lt;/p&gt;
&lt;p&gt;- **Severity:** High 
- **CWE:** CWE-502
- **Location:** `system/src/Grav/Framework/Cache/Adapter/FileCache.php`
- **Sink:** `unserialize($value, [&amp;#39;allowed_classes&amp;#39; =&amp;gt; true])`&lt;/p&gt;
&lt;p&gt;## Affected version(s)&lt;/p&gt;
&lt;p&gt;- **Affected:** `&amp;gt;= 1.7.44` and `&amp;lt;= 1.7.49.5` (verified in current codebase and changelog-covered releases).
- **Fixed:** No upstream fix identified in the reviewed branch at the time of analysis.
- **Notes:** Earlier `1.7.x` releases may also be affected, but were not fully back-traced in this review.&lt;/p&gt;
&lt;p&gt;## Notes
`allowed_classes =&amp;gt; true` allows object instantiation and does not constrain classes.&lt;/p&gt;
&lt;p&gt;## PoC (Primitive Demonstration)&lt;/p&gt;
&lt;p&gt;### Preconditions
- Local PHP runtime.
- Goal is to validate the deserialization primitive used in cache retrieval.&lt;/p&gt;
&lt;p&gt;### Steps
```bash
php -r &amp;#39;
class CacheWakeup { public function __wakeup(){ file_put_contents(&amp;#34;/tmp/grav_filecache_poc.txt&amp;#34;, &amp;#34;wakeup&amp;#34;); } }&lt;/p&gt;
&lt;p&gt;$payload = serialize(new CacheWakeup());
unserialize($payload, [&amp;#34;allowed_classes&amp;#34; =&amp;gt; true]);&lt;/p&gt;
&lt;p&gt;echo file_exists(&amp;#34;/tmp/grav_filecache_poc.txt&amp;#34;) ? &amp;#34;FILECACHE_UNSERIALIZE_TRIGGERED\n&amp;#34; : &amp;#34;FILECACHE_UNSERIALIZE_NOT_TRIGGERED\n&amp;#34;;
&amp;#39;
```&lt;/p&gt;
&lt;p&gt;### Expected Result
- Output contains: `FILECACHE_UNSERIALIZE_TRIGGERED`.&lt;/p&gt;
&lt;p&gt;### Interpretation
This reproduces the same unsafe primitive used by `FileCache::doGet()`:
`unserialize($value, [&amp;#39;allowed_classes&amp;#39; =&amp;gt; true])`.
If cache files are attacker-tampered, object magic methods may execute.&lt;/p&gt;
&lt;p&gt;## Exploit Preconditions
- Cache file poiso…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;# Insecure Deserialization in File Cache&lt;/p&gt;
&lt;p&gt;- **Severity:** High 
- **CWE:** CWE-502
- **Location:** `system/src/Grav/Framework/Cache/Adapter/FileCache.php`
- **Sink:** `unserialize($value, [&amp;#39;allowed_classes&amp;#39; =&amp;gt; true])`&lt;/p&gt;
&lt;p&gt;## Affected version(s)&lt;/p&gt;
&lt;p&gt;- **Affected:** `&amp;gt;= 1.7.44` and `&amp;lt;= 1.7.49.5` (verified in current codebase and changelog-covered releases).
- **Fixed:** No upstream fix identified in the reviewed branch at the time of analysis.
- **Notes:** Earlier `1.7.x` releases may also be affected, but were not fully back-traced in this review.&lt;/p&gt;
&lt;p&gt;## Notes
`allowed_classes =&amp;gt; true` allows object instantiation and does not constrain classes.&lt;/p&gt;
&lt;p&gt;## PoC (Primitive Demonstration)&lt;/p&gt;
&lt;p&gt;### Preconditions
- Local PHP runtime.
- Goal is to validate the deserialization primitive used in cache retrieval.&lt;/p&gt;
&lt;p&gt;### Steps
```bash
php -r &amp;#39;
class CacheWakeup { public function __wakeup(){ file_put_contents(&amp;#34;/tmp/grav_filecache_poc.txt&amp;#34;, &amp;#34;wakeup&amp;#34;); } }&lt;/p&gt;
&lt;p&gt;$payload = serialize(new CacheWakeup());
unserialize($payload, [&amp;#34;allowed_classes&amp;#34; =&amp;gt; true]);&lt;/p&gt;
&lt;p&gt;echo file_exists(&amp;#34;/tmp/grav_filecache_poc.txt&amp;#34;) ? &amp;#34;FILECACHE_UNSERIALIZE_TRIGGERED\n&amp;#34; : &amp;#34;FILECACHE_UNSERIALIZE_NOT_TRIGGERED\n&amp;#34;;
&amp;#39;
```&lt;/p&gt;
&lt;p&gt;### Expected Result
- Output contains: `FILECACHE_UNSERIALIZE_TRIGGERED`.&lt;/p&gt;
&lt;p&gt;### Interpretation
This reproduces the same unsafe primitive used by `FileCache::doGet()`:
`unserialize($value, [&amp;#39;allowed_classes&amp;#39; =&amp;gt; true])`.
If cache files are attacker-tampered, object magic methods may execute.&lt;/p&gt;
&lt;p&gt;## Exploit Preconditions
- Cache file poiso…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gwfr-jfjf-92vv</guid>
    </item>
  </channel>
</rss>
