{"id":"CVE-2026-7317","summary":"Grav CMS Cache Value FileCache.php doGet deserialization","details":"A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made public and could be used. Upgrading to version 2.0.0-beta.2 addresses this issue. The patch is identified as c66dfeb5f. The affected component should be upgraded.","aliases":["GHSA-gwfr-jfjf-92vv"],"modified":"2026-08-12T03:51:30.023094805Z","published":"2026-04-28T20:30:16.285Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.7.49.0"},{"last_affected":"1.7.49.0"},{"introduced":"2.0.0-beta.0"},{"last_affected":"2.0.0-beta.0"}]}],"cna_assigner":"VulDB","cwe_ids":["CWE-20","CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7317.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7317.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-gwfr-jfjf-92vv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7317"},{"type":"ADVISORY","url":"https://vuldb.com/submit/798732"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/359965"},{"type":"REPORT","url":"https://vuldb.com/vuln/359965/cti"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/c66dfeb5f"},{"type":"EVIDENCE","url":"https://github.com/devsamuelsantiago/grav-cms-filecache-object-injection"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getgrav/grav","events":[{"introduced":"466b2a16e86c397d4addc21d236ea84be31b7cf1"},{"fixed":"c66dfeb5f"}],"database_specific":{"extracted_events":[{"introduced":"1.7.49.1"},{"last_affected":"1.7.49.1"},{"introduced":"1.7.49.2"},{"last_affected":"1.7.49.2"},{"introduced":"1.7.49.3"},{"last_affected":"1.7.49.3"},{"introduced":"1.7.49.4"},{"last_affected":"1.7.49.4"},{"introduced":"1.7.49.5"},{"last_affected":"1.7.49.5"},{"introduced":"2.0.0-beta.1"},{"last_affected":"2.0.0-beta.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.7.49.1","1.7.49.2","1.7.49.3","1.7.49.4","1.7.49.5","2.0.0-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7317.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}