1. Overview
- Original Title: ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
- Source: BleepingComputer
- Publication Date: September 25, 2026
- Updated Date: None
- Severity: High
- Basis of Severity: Pre-authentication arbitrary file write in Grav core was officially confirmed as CVE-2026-42608, aligning with unauthorized file placement on the Clop site. Meanwhile, claims regarding full server control, source code, logs, and Tor private key theft originated from ShinyHunters and have not been independently verified.
- Original Article: ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
- Related Sources: ShinyHunters hacks Clop leak site, threatens to extort ransomware gang, Grav advisory GHSA-hmcx-ch82-3fv2, Grav 1.7.53.4 release
- Revision Rationale: Re-verified today's updates and switched the primary source to the September 25 exclusive report detailing the technical vector. Path input conditions, migration status, distinction between file placement and code execution, and ATT&CK mappings were updated.
2. Executive Summary
In Grav 1.7.43, CVE-2026-42608 combines the FormFlash session path with __unique_form_id__ to achieve unauthenticated arbitrary file write, matching the malicious file placement by ShinyHunters. Claims regarding private key theft and other impacts remain unverified.
3. Attack Flow
This section outlines the validation and implementation paths indicated by public sources. For the scope of observed activity in real-world environments, refer to "Attack Verification."
Arbitrary File Write via CVE-2026-42608
- An attacker sends an unauthenticated request to Grav FormFlash.
- According to public exploit details, a path traversal sequence is injected into
__unique_form_id__, redirecting the temporary upload path constructed with the session ID outside oftmp/forms. - Attacker-specified content is written to an arbitrary path, resulting in the publication of an unauthorized text file on the Clop site.
- Site defacement was also confirmed, though subsequent pathways for code execution and full server control have not been publicly disclosed.
4. Attacker Positioning and Execution Location
- Attackers send unauthenticated requests from external networks to the Grav site hosted on Tor.
- File writes occur on the server filesystem under the privileges of the Grav or web process.
5. Victim and Administrator Perspective
Victims
- On the existing Clop Tor site, defaced pages containing ShinyHunters' imagery and links were confirmed.
Administrators
- Unexpected files outside temporary directories and replaced public content serve as indicators of compromise. File placement alone does not confirm code execution on the server.
6. Success and Failure Conditions
Success Conditions
- Unauthenticated reachability to functionality utilizing FormFlash on vulnerable Grav 1.7 versions prior to 1.7.53.4.
- Write permissions granted to the web process for the attacker-specified path.
Failure Conditions and Risk Mitigation
- Update Grav to version 1.7.53.4 or later.
- Restrict web process write destinations and segregate permissions for the web root, logs, and Tor private keys.
7. What Happens Upon Success
- Arbitrary file write enables unauthorized file publication and content defacement.
- Claims of private key and server data theft have been asserted but remain unverified.
8. Observable Logs
Below are investigation perspectives for your organization. This does not indicate that all items were observed in actual incidents.
- Email: No reports indicate email was used as the initial entry vector.
- Proxy / SWG / DNS: Requests to FormFlash should be investigated via web server or application logs. Verifying POST parameters requires body logging, and standard access logs alone may be insufficient.
-
Endpoint / EDR: Check for new files outside
tmp/forms, child processes of the web process, and replaced public files. - Identity / IdP: Verify CMS or host management logins and token changes.
- SaaS / Cloud: If applicable, review hosting audit logs, modified public objects, and access records to sensitive information.
- Network: Check outbound traffic from the server. Observing encrypted Tor traffic alone does not reveal FormFlash request contents, so findings must be correlated with server-side records.
9. Attack Verification
Confirmed via Public Information
- Subsequent Compromise Confirmed: Public source BleepingComputer independently confirmed unauthorized file publication and defacement on the Clop site. Grav developers verified the vulnerability and attack description to reporters. Code execution, full server control, and private key theft have not been independently verified. (Scope: Clop's public Tor site and vendor interviews)
10. Investigation Playbook
Below are recommended investigation and response steps for your organization based on public information.
- Starting Point: Begin from related alerts, vulnerable assets, or indicators mentioned in primary sources.
- Initial Response: Verify the Grav version, reachability of FormFlash functionality, and web process write permissions and modification history.
- Endpoint: Preserve processes, files, services, persistence mechanisms, and EDR telemetry.
- Identity / Cloud: Check tokens, keys, logins, and SaaS or cloud audit logs.
- Subsequent Verification: Track data theft, lateral movement, additional payloads, and configuration changes.
- Containment: Isolate affected assets, apply patches, rotate credentials, and remove malicious modifications.
- Triage: Document contact, initial execution, authentication and malware success, data compromise, and subsequent compromise separately.
11. Defense and Detection Ideas
- Single Event: Detect path traversal requests to FormFlash, writes outside temporary directories, and replacement of public files.
- Timeline: Correlate suspicious requests, file creations, public content modifications, and subsequent processes or outbound traffic.
- Hunting: Cross-reference the impact period and asset inventory to proactively hunt for matching IoCs and behaviors.
- Log Gaps: Lack of required logs limits the ability to determine success phases. The absence of logs does not confirm a lack of execution.
- Priority Mitigations: Prioritize patch application, least privilege, outbound traffic control, and audit log retention.
12. Facts / Inference / Hypothesis
Facts
- BleepingComputer retrieved text files placed by ShinyHunters from Clop's existing onion address and confirmed subsequent site defacement.
- Grav confirmed CVE-2026-42608 as a pre-authentication arbitrary file write within core FormFlash path handling, rather than a Form plugin-specific issue.
- In interviews with BleepingComputer, ShinyHunters explained the vector utilizing Grav 1.7.43 and
__unique_form_id__, and Grav developers confirmed this explanation was correct. Although session IDs are also inputs to vulnerable path handling, it has not been demonstrated that both were manipulated simultaneously in real-world attacks. - This fix existed in Grav 2.0 beta2 but was not backported to the 1.7 branch until it was patched in version 1.7.53.4 on September 24, 2026.
- Full server control, source code,
/var/log, and Tor private key theft are claims made by ShinyHunters and have not been independently verified. - According to a follow-up report by BleepingComputer on September 25, Clop announced a new onion address and indicated plans to phase out the old address later. This does not constitute independent evidence verifying private key theft.
Inference
- Confirmed arbitrary file writes explain the placement of unauthorized text files, but do not independently prove full server reading, code execution, or private key acquisition.
Hypothesis
No additional hypotheses. Unverified items are documented in "Unresolved Questions and Further Investigation."
13. MITRE ATT&CK Mapping
| ID | Technique | Confidence | Basis |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | High | Grav developers confirmed the pre-authentication path traversal intrusion vector during interviews with BleepingComputer. |
| T1491.002 | Defacement: External Defacement | High | BleepingComputer confirmed external-facing Tor site defacement on Clop infrastructure. |
14. Unresolved Questions and Further Investigation
- Additional steps that led from arbitrary file write to defaced pages or code execution.
- Whether source code, logs, and Tor private keys were actually stolen.
- Specific details regarding host rebuilding and credential rotation associated with migration.
15. Impact on SOCs and Organizations
Japanese organizations utilizing Grav 1.7 should update to version 1.7.53.4 or later, and retroactively investigate path traversal requests and unexpected files around tmp/forms. Distinguish between successful file writes and code execution or sensitive information theft, and evaluate the scope of write access and read permissions for Tor private keys based on collected evidence.
16. Summary by Role
-
SOC: Correlate FormFlash path traversal,
__unique_form_id__, new files outsidetmp/forms, defacement, and subsequent processes. - Administrators: Update Grav to version 1.7.53.4 or later, segregate the web root and sensitive information from the web process, and verify host integrity.
- Users: If site content is defaced, verify operator announcements through alternative trusted channels.
Top comments (0)