Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-42608
CVE
CVE-2026-42608
View on NVD ↗
Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.
MITRE ATT&CK TTPs
1
T1195.001
Compromise Software Dependencies and Development Tools
Initial Access
Source Articles
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang's data leak site was compromised by the ShinyHunters extortion group through an unpatched path traversal vulnerability in Grav CMS version 1.7.43. ShinyHunters exploited the flaw to upload malicious files, deface the site, and claim theft of source code, plugins, server logs, and Tor private keys, subsequently issuing a ransom demand. Grav CMS confirmed the vulnerability, tracked as CVE-2026-42608, resides in the core of Grav and was fixed in Grav 2.0 but not backported to the 1.7 branch until version 1.7.53.4 was released following disclosure.
bleeping-computer
Sep 25, 2026