Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
2917
Downloads
3.3M
Verified
2917
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
1 rules matched. Showing 1 loaded rules.
Publish rule
CVE-2026-42845: Grav Unvalidated Stream File Readcve-2026-42845-grav-unvalidated-stream-file-read

An arbitrary file read and path traversal vulnerability was found. The code resolves a user-supplied path using a stream locator but fails to validate that the resulting path is within the expected root directory using `realpath()`. An attacker can pass directory traversal sequences or absolute paths to read sensitive files.

by Provallyupdated 2026-06-23Apache-2.0
7420 direct742 via packs
downloads
79quality
All matching rules loaded.