CVE-2026-74907: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
Verified against: getgrav/grav devel branch, GRAV_VERSION = "2.0.15", file `index.php
References
Code Behaviors & Features
Detect and mitigate CVE-2026-74907 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →