PT-2026-61930 · Grav · Grav

·

CVE-2026-65008

·

Published

2026-07-21

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav versions 2.0.4 through 2.0.6
Description Remote code execution is possible through the Blueprint::dynamicData() function in the system/src/Grav/Common/Data/Blueprint.php file. The issue occurs because a Class::method callable string and its arguments are passed directly to call user func array() without an allowlist. An authenticated user with admin.pages or api.pages.write permissions can insert a malicious callable directive into a page via the form plugin. This command then executes as the web-server user when any user, including unauthenticated visitors, accesses the affected page.
Recommendations Update Grav to version 2.0.7.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65008
GHSA-FJ2P-QJ2F-74V5

Affected Products

Grav