# Grav patches older CMS branch after Clop leak site breach

_Published Friday, September 25, 2026 at 9:07 PM EDT · Security · Latest · Tier 2 — Notable_

![Grav patches older CMS branch after Clop leak site breach — Primary](https://www.bleepstatic.com/content/hl-images/2024/12/10/hacker-box.jpg)

Grav has released version 1.7.53.4 to fix a path traversal flaw in its content management software after ShinyHunters used it to breach Clop's data leak site, BleepingComputer reports. The flaw lets an unauthenticated attacker manipulate a form upload path and write a file outside its intended directory.

Grav confirmed the attacker's description of the vulnerability and said the fix had already been included in its 2.x branch but had not reached version 1.7. Clop moved its leak site to a new Tor address. ShinyHunters claims it stole operational files and private keys; Clop disputes that valuable data was on the server.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/)

---
Canonical: https://techandbusiness.org/newswire/PtpFKmyGlfaYOHua6IBo-m
Published: 2026-09-26T01:07:46.351Z
Story chronology: 2026-09-25T20:57:55.000Z
Retrieved: 2026-09-26T03:05:55.513Z
Publisher: Tech & Business (techandbusiness.org)
