← Back to CVE List
Vulnerability Analysis
Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__

CVE-2026-61454

The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime environment type, and exact Grav and Admin2 version numbers, allowing an unauthenticated attacker to fingerprint the deployment and select version-specific exploits without reconnaissance.

Information Disclosure No Active Exploit Signals
CVSS Base Score
8.7
HIGH
Exploitability:-
Impact Score:-
Temporal Score:-
EPSS:0.24%

Threat Intelligence Signals

CISA KEV
No
KEV Date Added
Ransomware Use
KEV Due Date
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
0.239%
EPSS Percentile
14.9th pct
GitHub Severity
HIGH
SSVC Exploitation
Proof of Concept
SSVC Automatable
Yes
Vulnerability Class
Information Disclosure

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD