Beveiligingsadvies

CVE-2026-56709

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-25 01:30:10
Laatst bijgewerkt 2026-08-26 16:12:46
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.