CVE-2026-64850
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
Beschreibung
Grav ist eine auf Dateien basierende Webplattform. Vor Version 2.0.7 sendet Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php einen von einem Editor kontrollierten Class::method-Anbieter und Argumente an call_user_func_array(), ohne gefährliche Callback-Parameter abzulehnen. Ein Konto mit admin.pages oder api.pages.write kann Grav\Common\Utils::arrayFilterRecursive() als Trampolin verwenden, wobei system der Callback ist, einen Befehl in die Frontmatter einer Seite einfügt und diesen Befehl als Webserver-Benutzer ausführt, wenn die Seite angezeigt wird. Dieses Problem wurde in Version 2.0.7 behoben.
Metriken
Weakness-Klassen (CWE)
CWE-94Base
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-08-19 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://github.com/getgrav/grav/security/advisories/GHSA-fj2p-qj2f-74v5
- SSVC: {"id":"CVE-2026-64850","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…
- New CVE Received2026-08-19 16:18 UTC· security-advisories@github.com
- Affected: grav
- Description: Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous callback parameters. An account with admin.pages or api.pages.write can use Grav\Common\Utils::arrayFilterRecursive() as a trampoline with system as the callback, place a command in page frontmatter, and execute that command as the web server user when the page is viewed. This issue is fixed in version 2.0.7.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE: CWE-94
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
packagist
getgrav/grav0.8.0
packagist
getgrav/grav0.9.0
packagist
getgrav/grav0.9.1
packagist
getgrav/grav0.9.10
packagist
getgrav/grav0.9.11
packagist
getgrav/grav0.9.12
packagist
getgrav/grav0.9.13
packagist
getgrav/grav0.9.14
packagist
getgrav/grav0.9.15
packagist
getgrav/grav0.9.16
packagist
getgrav/grav0.9.17
packagist
getgrav/grav0.9.18
packagist
getgrav/grav0.9.19
packagist
getgrav/grav0.9.2
packagist
getgrav/grav0.9.20
packagist
getgrav/grav0.9.21
packagist
getgrav/grav0.9.22
packagist
getgrav/grav0.9.23
packagist
getgrav/grav0.9.24
packagist
getgrav/grav0.9.25
packagist
getgrav/grav0.9.26
packagist
getgrav/grav0.9.27
packagist
getgrav/grav0.9.28
packagist
getgrav/grav0.9.29
Quellen & Referenzen
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65008.jsonadvisory
- https://github.com/getgrav/grav/security/advisories/GHSA-fj2p-qj2f-74v5advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-65008advisory
- https://www.vulncheck.com/advisories/grav-before-remote-code-execution-via-blueprint-dynamicdataadvisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-64850advisory
- https://github.com/getgrav/grav/commit/acffa34cbb0787fee87c609e0d6289e904fee33cweb
- https://github.com/getgrav/gravpackage
- https://github.com/getgrav/grav/releases/tag/2.0.7web
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64850.jsonadvisory