CVE-2026-85601
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Sep 04, 2026
Vendor
unknown
Description
Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI schemes in plugin or theme changelogs to execute arbitrary code in authenticated admin sessions without requiring site access.