SCA: security update for getgrav/grav (GHSA-c2q3-p4jr-c55f)

medium Tenable Cloud Security Plugin ID 441209

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site
Scripting (XSS) vulnerability exists in the Grav CMS Form plugin's select field template. Taxonomy tag and
category values are rendered with the Twig |raw filter in the admin panel, bypassing the global autoescape
protection. An editor-level user can inject arbitrary JavaScript that executes in any administrator's
browser session when they view or edit any page in the admin panel. This vulnerability is fixed in 9.1.0.
(CVE-2026-42842)

Solution

Update the getgrav/grav library and its related packages to version 2.0.0-beta.2 or later.

See Also

https://github.com/advisories/GHSA-c2q3-p4jr-c55f

Plugin Details

Severity: Medium

ID: 441209

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 5/6/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.37

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-42842

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/5/2026

Vulnerability Publication Date: 5/5/2026

Reference Information

CVE: CVE-2026-42842

cwe: CWE-79