No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 19 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgrav
Getgrav grav |
|
| Vendors & Products |
Getgrav
Getgrav grav |
|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or protocol-relative Location target. Controller::execute() applies the field when taskTwofa_cancel() sets no redirect, and Grav::getRedirectResponse() accepts the target through Uri::isExternal(), enabling phishing redirects from a trusted Grav host. This issue is fixed in version 3.8.5. | |
| Title | Grav: Unauthenticated open redirect via login twofa_cancel _redirect | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-19T15:42:49.046Z
Reserved: 2026-06-09T20:50:36.876Z
Link: CVE-2026-53654
Updated: 2026-08-19T15:42:34.463Z
Status : Received
Published: 2026-08-19T16:17:46.150
Modified: 2026-08-19T16:17:46.150
Link: CVE-2026-53654
No data.
OpenCVE Enrichment
Updated: 2026-08-19T17:45:03Z