ShinyHunters Exploits Grav CMS Flaw to Breach Clop Leak Site
Share
The Clop ransomware gang has moved its data leak site to a new Tor address following a successful breach by the ShinyHunters extortion group. The intrusion was facilitated by an unpatched path traversal vulnerability in the Grav CMS software.
ShinyHunters defaced the Clop leak site, replacing its content with an Umbreon Pokémon logo and a link to the attackers’ own data leak platform. The threat actors claimed to have exfiltrated source code, server logs, Grav CMS plugins, and the private keys used by Clop for its Tor onion service. They subsequently issued a ransom demand, threatening to release the stolen data if Clop failed to pay.
Clop has confirmed that its Grav installation was not fully updated, though the group disputed the severity of the theft. Clop stated that the compromised server contained only website content and lacked any sensitive financial or operational data. The gang also denied any relationship or ongoing negotiations with ShinyHunters.
Technical details of the Grav CMS exploit
The vulnerability, identified as CVE-2026-42608, is an unauthenticated path traversal flaw located within the Grav core. The exploit targets the __unique_form_id__ parameter used in form upload handling. By supplying directory traversal sequences, such as ../../../, attackers could cause the CMS to create upload paths outside of the intended temporary directory, allowing files to be written to other locations within the installation.
Grav developers confirmed the accuracy of the exploitation details. While a fix had been integrated into the Grav 2.x major release earlier this year, the patch had not been backported to the 1.7 branch, leaving older installations like Clop’s vulnerable.
Mitigation and updates
Following the exploitation, developers backported the security fix to the 1.7 branch. Users currently running Grav 1.7.x are urged to upgrade to version 1.7.53.4 immediately to remediate the flaw. Those already using Grav 2.x releases have been protected by existing sanitisation measures for several months.




Leave a Reply