DKDKCISSPSearch
Ransomware

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

DKCISSP News DeskBleepingComputer26 Sept 2026, 2:27 am
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.

ShinyHunters later claimed on its own data leak site that it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop's Tor onion service.

Clop has now announced a new onion address and says the old domain will remain accessible temporarily before being retired.

When asked whether the group had determined how ShinyHunters breached the leak site, Clop confirmed that its Grav installation had not been fully updated.

Grav CMS has now confirmed that the vulnerability and exploitation details shared by ShinyHunters with BleepingComputer are accurate.

However, the Russian ransomware gang disputes ShinyHunters' claims that valuable operational or financial data was stolen from the compromised server.

"We didn't update the Grav plugin — though it happened eventually—but the server contained nothing but content (meaning there was absolutely no data or financial activity there, nor could there have been).

The group then issued a ransom demand, threatening to leak the stolen files if Clop did not pay.

The group specifically identified the __unique_form_id__ parameter and said the value was added into a temporary path like: ShinyHunters claimed that by supplying directory traversal sequences, such as ../../../shhq , for the unique form identifier, it could cause Grav to create an upload path outside the intended tmp/forms directory.

ShinyHunters told BleepingComputer that the compromised Clop server was running Grav CMS 1.7.43 and claimed it exploited an unauthenticated file upload flaw in Grav's form upload handling.

According to the threat actor, the vulnerable code used values supplied through form-related POST parameters when creating temporary upload directories without first validating them as safe filesystem path components.

The uploaded file could then be written elsewhere under the Grav installation.

Grav said the flaw is tracked as CVE-2026-42608 and is a path traversal vulnerability that was privately reported and fixed in Grav 2.0 (2.0.0-beta.2) earlier this year, with the advisory published on April 27.

What happened

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.

ShinyHunters later claimed on its own data leak site that it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop's Tor onion service.

What changed

Clop has now announced a new onion address and says the old domain will remain accessible temporarily before being retired.

When asked whether the group had determined how ShinyHunters breached the leak site, Clop confirmed that its Grav installation had not been fully updated.

Grav CMS has now confirmed that the vulnerability and exploitation details shared by ShinyHunters with BleepingComputer are accurate.

Who is affected

However, the Russian ransomware gang disputes ShinyHunters' claims that valuable operational or financial data was stolen from the compromised server.

"We didn't update the Grav plugin — though it happened eventually—but the server contained nothing but content (meaning there was absolutely no data or financial activity there, nor could there have been).

Why it matters

The group then issued a ransom demand, threatening to leak the stolen files if Clop did not pay.

The group specifically identified the __unique_form_id__ parameter and said the value was added into a temporary path like: ShinyHunters claimed that by supplying directory traversal sequences, such as ../../../shhq , for the unique form identifier, it could cause Grav to create an upload path outside the intended tmp/forms directory.

Technical details

ShinyHunters told BleepingComputer that the compromised Clop server was running Grav CMS 1.7.43 and claimed it exploited an unauthenticated file upload flaw in Grav's form upload handling.

According to the threat actor, the vulnerable code used values supplied through form-related POST parameters when creating temporary upload directories without first validating them as safe filesystem path components.

The uploaded file could then be written elsewhere under the Grav installation.

Response

Grav said the flaw is tracked as CVE-2026-42608 and is a path traversal vulnerability that was privately reported and fixed in Grav 2.0 (2.0.0-beta.2) earlier this year, with the advisory published on April 27.

The fix added a sanitizeId() function that only accepts identifiers matching the allowlist: Grav confirmed that this sanitization method is the same mitigation described by ShinyHunters to BleepingComputer.

What security teams should do

Grav is urging anyone still running the 1.7 branch to upgrade to version 1.7.53.4.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Attribution

BleepingComputer: The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN RANSOMWARE

More cybersecurity reporting

Police dismantle KillSec ransomware gang allegedly led by 16-year-oldBleepingComputer · 1 Oct 2026, 7:55 pmINC Ransomware Attack: Impact, Victims, Recovery | HuntressHuntress · 1 Oct 2026, 5:30 amJapan's Keio confirms ransomware attack disrupted business systemsBleepingComputer · 29 Sept 2026, 2:26 amShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacksBleepingComputer · 27 Sept 2026, 12:33 am