PT-2026-61930 · Grav · Grav
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav versions 2.0.4 through 2.0.6
Description
Remote code execution is possible through the
Blueprint::dynamicData() function in the system/src/Grav/Common/Data/Blueprint.php file. The issue occurs because a Class::method callable string and its arguments are passed directly to call user func array() without an allowlist. An authenticated user with admin.pages or api.pages.write permissions can insert a malicious callable directive into a page via the form plugin. This command then executes as the web-server user when any user, including unauthenticated visitors, accesses the affected page.Recommendations
Update Grav to version 2.0.7.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav