{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agetgravgrav/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-64850"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav (\u003c 2.0.7)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","cms","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eGrav CMS versions prior to 2.0.7 are susceptible to a remote code execution (RCE) vulnerability identified as CVE-2026-64850. The vulnerability stems from the \u003ccode\u003eBlueprint::dynamicData()\u003c/code\u003e method, which performs insufficient validation on class method inputs. Specifically, the application uses \u003ccode\u003ecall_user_func_array()\u003c/code\u003e with input derived from page frontmatter without implementing an allowlist.\u003c/p\u003e\n\u003cp\u003eAn attacker with \u003ccode\u003eadmin.pages\u003c/code\u003e or \u003ccode\u003eapi.pages.write\u003c/code\u003e permissions can craft a malicious page configuration that designates \u003ccode\u003eGrav\\Common\\Utils::arrayFilterRecursive\u003c/code\u003e as a callable to execute system-level commands. Because the frontmatter is processed when a page is rendered, the payload executes with the privileges of the web-server user whenever a visitor (including unauthenticated users) requests the page. This vulnerability effectively escalates a compromise of administrative page-editing rights to full system-level code execution on the underlying server.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid \u003ccode\u003eadmin.pages\u003c/code\u003e or \u003ccode\u003eapi.pages.write\u003c/code\u003e permissions, likely via compromised administrative credentials.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the Grav administrative interface and navigates to the page creation or editing module.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a custom page containing malicious YAML frontmatter, specifically targeting the form plugin's field definitions.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a \u003ccode\u003edata-opts@\u003c/code\u003e directive into the frontmatter, pointing to \u003ccode\u003eGrav\\Common\\Utils::arrayFilterRecursive\u003c/code\u003e as the callable.\u003c/li\u003e\n\u003cli\u003eAttacker embeds the target system command (e.g., \u003ccode\u003eid\u003c/code\u003e) within the frontmatter payload, passing it as the primary argument to the function.\u003c/li\u003e\n\u003cli\u003eAttacker saves the page configuration to the Grav CMS data store.\u003c/li\u003e\n\u003cli\u003eAttacker (or any subsequent visitor) triggers a GET request to the path corresponding to the malicious page.\u003c/li\u003e\n\u003cli\u003eGrav CMS processes the page frontmatter, invokes the malicious callable via \u003ccode\u003edynamicData()\u003c/code\u003e, and executes the command on the web server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary remote code execution on the host server under the context of the web-server user (e.g., \u003ccode\u003ewww-data\u003c/code\u003e or \u003ccode\u003eapache\u003c/code\u003e). This allows for full system control, potential data exfiltration, or lateral movement within the hosting environment. Any user with page-editing privileges can turn a legitimate site into a persistent execution platform that triggers malicious commands upon every page view.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Grav CMS installations to version 2.0.7 or later to address the insecure \u003ccode\u003ecall_user_func_array\u003c/code\u003e invocation in \u003ccode\u003eBlueprint.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit current administrative accounts for \u003ccode\u003eadmin.pages\u003c/code\u003e or \u003ccode\u003eapi.pages.write\u003c/code\u003e permissions to ensure they are restricted to authorized personnel only.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for POST requests to the Grav admin interface followed by anomalous GET requests to newly created or modified pages that may indicate payload testing.\u003c/li\u003e\n\u003cli\u003eReview system-level web server logs for suspicious process execution (e.g., \u003ccode\u003eid\u003c/code\u003e, \u003ccode\u003ewhoami\u003c/code\u003e, \u003ccode\u003ecurl\u003c/code\u003e, \u003ccode\u003ewget\u003c/code\u003e) originating from the web server process user.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T18:04:09Z","date_published":"2026-09-02T18:04:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-grav-rce/","summary":"An attacker with administrative page-editing permissions can achieve remote code execution in Grav versions prior to 2.0.7 by injecting arbitrary callables into page frontmatter, which are subsequently triggered by visitor requests.","title":"Remote Code Execution in Grav via Blueprint dynamicData","url":"https://feed.craftedsignal.io/briefs/2026-09-grav-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}