Remote Code Execution Vulnerability in Grav by GetGrav
CVE-2026-65008
Key Information:
Badges
What is CVE-2026-65008?
Grav version 2.0.4 is susceptible to a remote code execution vulnerability that arises from the improper handling of callable strings in Blueprint::dynamicData(). This vulnerability allows authenticated users with specific permissions (admin.pages or api.pages.write) to inject malicious commands into the page frontmatter. When accessed by any user, including someone unauthenticated, these commands are executed with the privileges of the web-server user, potentially compromising the security of the web server. This issue has been addressed in Grav version 2.0.7.
Affected Version(s)
grav 0 < 2.0.7
grav 2.0.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
