This release includes 1 security fix for security teams reviewing exposed deployments.
Published 26d
Documentation
✓ No known CVEs patched
This release patches 1 known CVE
Topics
cms
content
content-management
doctrine
flat-file
grav
+9 more
markdown
php
php7
symfony
twig
website
website-builder
website-generation
yaml
Affected surfaces
auth
Summary
AI summaryProfile avatars now display correctly after fixing folder hardening that previously returned a 403.
Full changelog
Bugfix
- A page's
translatedLanguages()now returns each language's own route, so a translation with a localizedslug:produces the correct cross-language link instead of repeating the default language's URL. Fixes getgrav/grav#4183. - [security] Profile avatars display again instead of returning a 403; the folder hardening that locked down
user/accountsnow makes a narrow exception for avatar images while account data such as password hashes stays blocked, and existing sites self-heal on upgrade. Fixes getgrav/grav#4185. - Loading a page no longer fails with a "Failed to write cache file" error when Grav can't save the compiled template cache, such as on a shared folder, a full disk, or during a save-then-reload race; the page still renders and the problem is logged instead. Fixes getgrav/grav#4184.
Security Fixes
- Fix for profile avatar display – folder hardening exception added so avatars are no longer blocked by a 403 while other account data remains protected (getgrav/grav#4185).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About grav
Modern, Crazy Fast, Ridiculously Easy and Amazingly Powerful Flat-File CMS powered by PHP, Markdown, Twig, and Symfony
Beta — feedback welcome: [email protected]