Grav is Vulnerable to XXE via SVG Upload (CVE-2026-56701)
Grav CMS versions prior to 2.0.0-beta.2 are vulnerable to an XML External Entity (XXE) injection via SVG file uploads. Authenticated attackers with admin panel access can upload malicious SVG files that exploit improper XML parsing to read arbitrary server files, perform SSRF, or cause denial of service. The vulnerability arises from using simplexml_load_string without disabling external entity loading. A fix has been applied in Grav 2.0.0-beta.2 and the associated SVG sanitizer library to strip dangerous XML declarations and disable external entity processing.
AI Analysis
Technical Summary
Grav CMS versions before 2.0.0-beta.2 improperly process uploaded SVG files using simplexml_load_string without disabling external entity loading, allowing authenticated attackers to perform XXE attacks. This enables reading sensitive files such as /etc/passwd, user account YAML files, system configuration, and environment secrets. The vulnerability also allows SSRF and potential denial of service via billion laughs attacks. The issue is fixed by stripping DOCTYPE and ENTITY declarations before parsing and using libxml flags (LIBXML_NONET, LIBXML_NOERROR, LIBXML_NOWARNING) and disabling entity loaders on PHP < 8. The fix is implemented in Grav core 2.0.0-beta.2 and the dom-sanitizer library.
Potential Impact
An authenticated attacker with admin panel access can exploit this vulnerability to read arbitrary files on the server, including sensitive configuration and credential files, potentially leading to credential disclosure and system information leakage. The attacker can also perform server-side request forgery (SSRF) to access internal services and cause denial of service through recursive entity expansion attacks.
Mitigation Recommendations
A security fix is available and has been applied in Grav CMS version 2.0.0-beta.2 and the updated dom-sanitizer library. The fix strips DOCTYPE and ENTITY declarations from SVG files before XML parsing and disables external entity loading, preventing XXE exploitation. Users should upgrade to Grav 2.0.0-beta.2 or later and ensure the updated dom-sanitizer library is in use. No additional mitigation actions are required once patched.
Grav is Vulnerable to XXE via SVG Upload (CVE-2026-56701)
Description
Grav CMS versions prior to 2.0.0-beta.2 are vulnerable to an XML External Entity (XXE) injection via SVG file uploads. Authenticated attackers with admin panel access can upload malicious SVG files that exploit improper XML parsing to read arbitrary server files, perform SSRF, or cause denial of service. The vulnerability arises from using simplexml_load_string without disabling external entity loading. A fix has been applied in Grav 2.0.0-beta.2 and the associated SVG sanitizer library to strip dangerous XML declarations and disable external entity processing.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Grav CMS versions before 2.0.0-beta.2 improperly process uploaded SVG files using simplexml_load_string without disabling external entity loading, allowing authenticated attackers to perform XXE attacks. This enables reading sensitive files such as /etc/passwd, user account YAML files, system configuration, and environment secrets. The vulnerability also allows SSRF and potential denial of service via billion laughs attacks. The issue is fixed by stripping DOCTYPE and ENTITY declarations before parsing and using libxml flags (LIBXML_NONET, LIBXML_NOERROR, LIBXML_NOWARNING) and disabling entity loaders on PHP < 8. The fix is implemented in Grav core 2.0.0-beta.2 and the dom-sanitizer library.
Potential Impact
An authenticated attacker with admin panel access can exploit this vulnerability to read arbitrary files on the server, including sensitive configuration and credential files, potentially leading to credential disclosure and system information leakage. The attacker can also perform server-side request forgery (SSRF) to access internal services and cause denial of service through recursive entity expansion attacks.
Mitigation Recommendations
A security fix is available and has been applied in Grav CMS version 2.0.0-beta.2 and the updated dom-sanitizer library. The fix strips DOCTYPE and ENTITY declarations from SVG files before XML parsing and disables external entity loading, preventing XXE exploitation. Users should upgrade to Grav 2.0.0-beta.2 or later and ensure the updated dom-sanitizer library is in use. No additional mitigation actions are required once patched.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3446-6mgw-f79p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-56701"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ab4be99f7a7c54106f0dfa6
Added to database: 09/24/2026, 06:09:29 UTC
Last enriched: 09/24/2026, 07:00:33 UTC
Last updated: 09/24/2026, 17:47:33 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.