This release includes 1 security fix for security teams reviewing exposed deployments.
Published 26d
Documentation
✓ No known CVEs patched
This release patches 1 known CVE
Topics
cms
content
content-management
doctrine
flat-file
grav
+9 more
markdown
php
php7
symfony
twig
website
website-builder
website-generation
yaml
Affected surfaces
auth
Summary
AI summaryFolder‑storage user avatars are now served correctly instead of returning a 403.
Full changelog
Bugfix
- [security] Flex user avatars stored under
user/accounts/<username>/(folder storage) are now served too; the 2.0.5 avatar carve-out only covered the flatfileuser/accounts/avatars/layout, so folder-storage avatars kept returning a 403. Existing sites self-heal on upgrade. Fixes getgrav/grav#4185.
Security Fixes
- Folder‑storage avatars under `user/accounts/ /` are now served, fixing a permission bypass (getgrav/grav#4185).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About grav
Modern, Crazy Fast, Ridiculously Easy and Amazingly Powerful Flat-File CMS powered by PHP, Markdown, Twig, and Symfony
Beta — feedback welcome: [email protected]