Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
Grav versions before 2.0.14 have a stored cross-site scripting (XSS) vulnerability in the Security::detectXss() function. A single invalid UTF-8 byte in page content causes all XSS detection patterns to fail, bypassing the XSS safety check. An authenticated user with page-edit permissions but without the XSS whitelist privilege can exploit this to store malicious JavaScript that executes in visitors' browsers.
AI Analysis
Technical Summary
Grav prior to version 2.0.14 contains a stored XSS vulnerability in the Security::detectXss() function located in system/src/Grav/Common/Security.php. The vulnerability arises because all XSS detection patterns use the PCRE /u (UTF-8) modifier. If page content contains a single invalid UTF-8 byte, preg_match() returns false for every pattern, causing the Validation::checkSafety() XSS safety gate to be silently bypassed. This allows an authenticated attacker with page-edit permissions (but without the security.xss_whitelist privilege) to store malicious JavaScript that executes when a visitor views the affected page.
Potential Impact
An attacker with authenticated page-edit permissions can store malicious JavaScript on the site that executes in the browsers of visitors viewing the affected page. This bypasses the intended XSS protection mechanism, potentially leading to client-side script execution, data theft, or session hijacking. The vulnerability requires authentication and specific permissions, limiting the attack surface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the advisory is a duplicate and withdrawn, consult the original advisory GHSA-q2j8-x8hf-63ch for official patch or mitigation details. Until patched, restrict page-edit permissions to trusted users and monitor for suspicious content.
Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
Description
Grav versions before 2.0.14 have a stored cross-site scripting (XSS) vulnerability in the Security::detectXss() function. A single invalid UTF-8 byte in page content causes all XSS detection patterns to fail, bypassing the XSS safety check. An authenticated user with page-edit permissions but without the XSS whitelist privilege can exploit this to store malicious JavaScript that executes in visitors' browsers.
CVSS v3.1
Score 5.4medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Grav prior to version 2.0.14 contains a stored XSS vulnerability in the Security::detectXss() function located in system/src/Grav/Common/Security.php. The vulnerability arises because all XSS detection patterns use the PCRE /u (UTF-8) modifier. If page content contains a single invalid UTF-8 byte, preg_match() returns false for every pattern, causing the Validation::checkSafety() XSS safety gate to be silently bypassed. This allows an authenticated attacker with page-edit permissions (but without the security.xss_whitelist privilege) to store malicious JavaScript that executes when a visitor views the affected page.
Potential Impact
An attacker with authenticated page-edit permissions can store malicious JavaScript on the site that executes in the browsers of visitors viewing the affected page. This bypasses the intended XSS protection mechanism, potentially leading to client-side script execution, data theft, or session hijacking. The vulnerability requires authentication and specific permissions, limiting the attack surface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the advisory is a duplicate and withdrawn, consult the original advisory GHSA-q2j8-x8hf-63ch for official patch or mitigation details. Until patched, restrict page-edit permissions to trusted users and monitor for suspicious content.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-993v-76jg-67xr
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6aac8de855bf5e2cf54900d1
Added to database: 09/18/2026, 01:03:36 UTC
Last enriched: 09/18/2026, 01:26:06 UTC
Last updated: 09/18/2026, 01:26:06 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.