Vulnerability
Published 2026-09-25
Verified 2026-09-27

Grav CMS CVE-2026-42608 (CVSS 8.8): unauth FormFlash path traversal → arbitrary write — exploited on Clop leak site; fix 1.7.53.4 / 2.0.0-beta.2+

BleepingComputer (25 September 2026) reports ShinyHunters compromised and defaced the Clop ransomware data-leak site by exploiting an unauthenticated path-traversal / arbitrary file-write flaw in Grav CMS core FormFlash. Clop confirmed the prior Grav install was not fully updated (actor claimed 1.7.43) and moved to a new Tor onion; Clop disputes that operational or financial data was stolen and denies talks with ShinyHunters. Grav told BC the actor’s technical description is accurate and tracks the issue as CVE-2026-42608 (GHSA-hmcx-ch82-3fv2; advisory 27 Apr 2026): unauthenticated manipulation of form identifiers (e.g. __unique_form_id__ / __form-flash-id) lets attackers traverse out of tmp/forms and write under the Grav install. Fixed in Grav 2.0.0-beta.2 earlier; the 1.7 line lacked the backport until Grav released 1.7.53.4 after BC shared exploitation details (BC: “yesterday” relative to 25 Sep). Bug is in Grav core, not the Form plugin. CVE.report / GitHub CNA: CVSS 4.0 8.8 HIGH (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/…). Primary wire: BleepingComputer; vendor: Grav GHSA + 1.7.53.4 release; metadata: CVE.report.

Product
Grav CMS (core FormFlash component)
Versions
Affected: Grav core before 2.0.0-beta.2 on the 2.x line; 1.7.x before 1.7.53.4 (Clop site claimed on 1.7.43). Form plugin version does not determine exposure — core version matters (Grav to BC).
CVSS
(CVSS 4.0 HIGH, GitHub CNA / CVE.report)
Exploited in Australia?
unknown
Patch to
Upgrade Grav 1.7.x to 1.7.53.4 or later; Grav 2.x to 2.0.0-beta.2 or later current 2.x. Inventory internet-facing Grav (including onion/hidden services). Hunt unexpected paths/files under the Grav install outside tmp/forms; rotate secrets if write confirmed; do not rely on Form plugin version alone.

Primary: BleepingComputer — ShinyHunters hacked Clop leak site via Grav path traversal (25 Sep 2026) · Vendor: Grav GHSA-hmcx-ch82-3fv2 / CVE-2026-42608 (patched 2.0.0-beta.2, 1.7.53.4) · CVE: CVE-2026-42608 · Grav — 1.7.53.4 release (1.7-line backport); also CVE.report CVE-2026-42608

vulnerabilities australia cloud