PT-2026-71999 · Grav · Grav-Plugin-Api
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav API plugin versions prior to 1.0.13
Description
Failure to enforce API key scope caps in
ConfigController super-scope gates allows scoped keys to modify scheduler configuration. An attacker possessing a scoped api.config.write key can inject arbitrary commands into scheduler.custom jobs, which are then executed via Symfony Process, leading to remote code execution.Recommendations
Update Grav API plugin to version 1.0.13 or later.
Exploit
Fix
RCE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav-Plugin-Api