Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-56709

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Aug 25, 2026
Vendor unknown

Description

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.

References