Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows. | |
| Title | Grav before 3.9.2 Host Header Injection via sendInvitationEmail | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-350 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:10.057Z
Reserved: 2026-06-22T18:48:27.060Z
Link: CVE-2026-56709
No data.
Status : Received
Published: 2026-08-25T02:16:42.930
Modified: 2026-08-25T02:16:42.930
Link: CVE-2026-56709
No data.
OpenCVE Enrichment
No data.
Weaknesses