CVE-2026-65008
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
Beschreibung
Grav 2.0.4 (korrigiert in 2.0.7) enthält eine Schwachstelle zur Fernausführung von Code in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), die einen Callable-String der Form Class::method und seine Argumente direkt an call_user_func_array() übergibt, ohne jegliche Whitelist. Da das Formular-Plugin die Seitenvorderseite durch diesen Pfad leitet, kann ein authentifizierter Account mit der Berechtigung admin.pages (oder api.pages.write) einen bösartigen Callable-Befehl in einer Seite platzieren. Der Befehl wird dann als Webserver-Benutzer ausgeführt, sobald jemand — einschließlich eines nicht-authentifizierten Besuchers — die Seite aufruft.
Metriken
Weakness-Klassen (CWE)
CWE-94Base
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-07-22 15:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://github.com/getgrav/grav/security/advisories/GHSA-fj2p-qj2f-74v5
- SSVC: {"id":"CVE-2026-65008","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalI…
- New CVE Received2026-07-21 12:19 UTC· disclosure@vulncheck.com
- Affected: grav
- Description: Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because the form plugin routes page frontmatter through this path, an authenticated account with the admin.pages (or api.pages.write) permission can plant a malicious callable directive in a page. The command then executes as the web-server user whenever anyone — including an unauthenticated visitor — accesses the page.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
packagist
getgrav/grav0.8.0
packagist
getgrav/grav0.9.0
packagist
getgrav/grav0.9.1
packagist
getgrav/grav0.9.10
packagist
getgrav/grav0.9.11
packagist
getgrav/grav0.9.12
packagist
getgrav/grav0.9.13
packagist
getgrav/grav0.9.14
packagist
getgrav/grav0.9.15
packagist
getgrav/grav0.9.16
packagist
getgrav/grav0.9.17
packagist
getgrav/grav0.9.18
packagist
getgrav/grav0.9.19
packagist
getgrav/grav0.9.2
packagist
getgrav/grav0.9.20
packagist
getgrav/grav0.9.21
packagist
getgrav/grav0.9.22
packagist
getgrav/grav0.9.23
packagist
getgrav/grav0.9.24
packagist
getgrav/grav0.9.25
packagist
getgrav/grav0.9.26
packagist
getgrav/grav0.9.27
packagist
getgrav/grav0.9.28
packagist
getgrav/grav0.9.29
Quellen & Referenzen
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65008.jsonadvisory
- https://github.com/getgrav/grav/security/advisories/GHSA-fj2p-qj2f-74v5advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-65008advisory
- https://www.vulncheck.com/advisories/grav-before-remote-code-execution-via-blueprint-dynamicdataadvisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-64850advisory
- https://github.com/getgrav/grav/commit/acffa34cbb0787fee87c609e0d6289e904fee33cweb
- https://github.com/getgrav/gravpackage
- https://github.com/getgrav/grav/releases/tag/2.0.7web
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64850.jsonadvisory