Grav CMS Path Traversal Exploit Compromises Clop Ransomware Site

Grav CMS Path Traversal Exploit Compromises Clop Ransomware Site

ShinyHunters exploited an unpatched Grav CMS vulnerability to breach the Clop ransomware leak site and steal operational data.

The ShinyHunters extortion group successfully compromised the data leak infrastructure of the rival Clop ransomware gang by exploiting a critical security flaw in the Grav Content Management System (CMS). This incident highlights how unpatched software vulnerabilities can expose even high-profile threat actors to counter-attacks and data theft. The breach occurred earlier this month when ShinyHunters uploaded a small text file to the Clop server, eventually replacing the entire interface with a defacement page featuring an Umbreon Pokémon logo and a link to their own leak site.

According to technical details provided by ShinyHunters to BleepingComputer, the attackers targeted a Grav CMS installation running version 1.7.43. The vulnerability used was an unauthenticated path traversal flaw located within the core software rather than a specific plugin. The exploit relied on how Grav handled temporary file uploads via form parameters. Specifically, the code took values from the __unique_form_id__ POST parameter and inserted them directly into a temporary directory path without validating whether those values contained safe filesystem components. By injecting directory traversal sequences such as ../../../shhq into this parameter, the attackers forced the system to create upload paths outside the intended secure tmp/forms directory. This allowed them to write files to arbitrary locations within the Grav installation structure.

Grav CMS developers have confirmed that the exploitation method described by ShinyHunters is accurate. The vulnerability has been assigned the identifier CVE-2026-42608. It was originally fixed in Grav version 2.0, specifically in the 2.0.0-beta.2 release, which introduced a sanitizeId() function. This function restricts identifiers to a strict allowlist of alphanumeric characters, commas, underscores, and hyphens, limiting the length to 64 characters. However, this security patch was not backported to the older 1.7 branch. Consequently, sites still running legacy versions like 1.7.43 remained vulnerable despite the fix being available in newer releases. The advisory for the original fix was published on April 27.

Following the confirmation of the vulnerability details, Grav developers acted quickly to address the gap in the older branch. They backported the sanitization fix to the 1.7 line and released version 1.7.53.4 to protect existing users. Grav emphasized that the bug resides in the core software, meaning the version of the Form plugin does not determine vulnerability status; only the core version matters. Users on the current 2.x releases were already protected from this specific attack vector for several months.

In response to the breach, Clop announced a new Tor onion address for its leak site while keeping the old domain accessible temporarily. The group denied any relationship or ongoing negotiations with ShinyHunters, stating they had never worked together and provided no information to the attackers. Clop disputed ShinyHunters' claims that valuable financial or operational data was stolen, asserting that the server only contained static content. Despite these denials, Clop entries were quietly removed from ShinyHunters' leak site, a common indicator of active negotiation or settlement between groups. ShinyHunters declined further comment regarding the removal. For website owners and IT teams, this event underscores the necessity of maintaining up-to-date software versions and understanding the difference between plugin updates and core security patches to prevent similar unauthorized access.

Website administrators managing Grav-based sites should verify their core version immediately and upgrade to 1.7.53.4 or later if they are on the legacy branch. Regularly auditing software versions against vendor advisories is essential to closing known security gaps before they can be exploited by malicious actors seeking to compromise server integrity.

Si të Mbroheni

  1. Check your website's content management system version in the administration dashboard settings.
  2. Update your core software to the latest stable version recommended by the developer immediately.
  3. Do not rely solely on updating plugins; ensure the main system files are also patched.
  4. Review your server logs for any unusual file upload activities or unauthorized access attempts.
  5. Enable automatic update notifications for your hosting platform to stay informed about critical security fixes.

Dobësitë & Zgjidhjet

Termat e Shpjeguar

  • Path Traversal An attack where a user tries to access files outside the intended directory by manipulating file paths with special characters.
  • Grav CMS A flat-file content management system that allows website creation without using a traditional database.
  • Tor Onion Address A web address ending in .onion that routes traffic through the Tor network to provide anonymity and privacy.
  • Defacement The act of altering the visual appearance of a website, often to display a message or logo from the attacker.
  • POST Parameter Data sent from a web form to a server using the HTTP POST method, often used to submit information like usernames or file uploads.

Shërbime AEU të lidhura

  • AEU Panel Paneli i kontrollit për hosting-un e menaxhuar
  • AEU-I Konsulencë IT dhe sigurie