CVE-2026-75834: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
- Type: Stored XSS (CWE-79)
- Auth required: Page-edit (“publisher”) account, not super-admin
- Consequence: Arbitrary JavaScript execution in any visitor’s browser, including a super-admin who views the page — a cross-trust-boundary escalation from publisher to admin-equivalent action capability.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-75834 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →