Information Exposure Affecting getgrav/grav package, versions >=1.7.0, <1.7.53.4>=2.0.0, <2.0.22


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.5% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-GETGRAVGRAV-20079170
  • published24 Sept 2026
  • disclosed17 Sept 2026
  • creditUnknown

Introduced: 17 Sep 2026

NewCVE-2026-92916  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade getgrav/grav to version 1.7.53.4, 2.0.22 or higher.

Overview

getgrav/grav is a Modern, Crazy Fast, Ridiculously Easy and Amazingly Powerful Flat-File CMS.

Affected versions of this package are vulnerable to Information Exposure in the InitializeProcessor::handleDebuggerRequest process when the debugger is enabled. An attacker can access sensitive information, including session cookies, plaintext credentials, and configuration secrets, by sending unauthenticated requests to the /__clockwork/ endpoint. This is only exploitable if the debugger is enabled (system.debugger.enabled: true), which is not the default configuration.

Workaround

This vulnerability can be mitigated by disabling the debugger (debugger.enabled: false) or blocking access to /__clockwork/ at the web server or CDN.

References

CVSS Base Scores

version 4.0
version 3.1