CVE-2026-85602: Grav Form Plugin reCAPTCHA v3 Authentication Bypass, 9.3 rating 🔥
The Grav Form plugin selects which reCAPTCHA version to use for validation based solely on the presence of a specific response field key in the submitted payload. This allows an anonymous attacker to bypass reCAPTCHA v3 bot protection.
Search at Netlas.io:
👉 Link: https://nt.ls/VcB4a
👉 Dork: tag.name:"grav"
Vendor's advisory :
https://github.com/getgrav/grav/security/advisories/GHSA-89j6-8h38-2cc3
Post #625
493

- 🔥 4
- ❤ 1