Remote Code Execution in Grav Email Plugin by Grav
CVE-2026-75574
8.7HIGH
What is CVE-2026-75574?
The Grav Email plugin prior to version 4.2.2 has a critical flaw that enables an authenticated remote user, possessing only api.access and api.pages.write permissions, to manipulate Email action parameters. The flaw allows the insertion of a Twig expression into the header.form.process.email.body, leading to execution of arbitrary operating-system commands on the server, thereby compromising the security of the application.
Affected Version(s)
grav 0 < 4.2.2
grav 4.2.2
