Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-62668

Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols
Back to all
CVE

CVE-2026-62668

Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTERVALIDATEURL syntax validation, and WebhookDispatcher.php initializes cURL without CURLOPTPROTOCOLS or CURLOPTREDIR_PROTOCOLS restrictions. An account with api.webhooks.write can submit file, dict, gopher, private-network, or link-local targets, retrieve local files and delivery response bodies, and pivot requests to internal services or cloud metadata endpoints. This issue is fixed in version 1.0.6.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.4
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/getgrav/grav-plugin-api/releases/tag/1.0.6, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62668.json, https://github.com/getgrav/grav/security/advisories/GHSA-58q8-f7v4-w2vf, https://nvd.nist.gov/vuln/detail/CVE-2026-62668, https://github.com/getgrav/grav-plugin-api/commit/dfcc947f0d6758772caac290c68fe8d4c4a4874e

Severity

8.1

CVSS Score
0
10

Basic Information

Base CVSS
8.1
EPSS Probability
0.00395%
EPSS Percentile
0.32467%
Introduced Version
0
Fix Available
c22d77d2ec2a9202d9f005f4ceda9c1483921286,fe5146a3efeb39d1f405499188e5270bc002b0a6

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading