{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/grav--2.0.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-65008"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav \u003c 2.0.7"],"_cs_severities":["critical"],"_cs_tags":["web-exploitation","rce","php"],"_cs_type":"advisory","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eA critical remote code execution (RCE) vulnerability, identified as CVE-2026-65008, has been discovered in Grav versions prior to 2.0.7. The flaw resides within the \u003ccode\u003eBlueprint::dynamicData()\u003c/code\u003e function in \u003ccode\u003esystem/src/Grav/Common/Data/Blueprint.php\u003c/code\u003e, which unsafely passes a \u003ccode\u003eClass::method\u003c/code\u003e callable string and its arguments directly to PHP's \u003ccode\u003ecall_user_func_array()\u003c/code\u003e without proper validation or an allowlist. This oversight enables an authenticated attacker with \u003ccode\u003eadmin.pages\u003c/code\u003e or \u003ccode\u003eapi.pages.write\u003c/code\u003e permissions to inject a malicious callable directive into a page's frontmatter. Subsequently, when any user, including unauthenticated visitors, accesses the compromised page, the embedded malicious command executes on the web server with the privileges of the web-server user, allowing for arbitrary code execution.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains authenticated access to a Grav installation with \u003ccode\u003eadmin.pages\u003c/code\u003e or \u003ccode\u003eapi.pages.write\u003c/code\u003e permissions.\u003c/li\u003e\n\u003cli\u003eThe attacker accesses the Grav administration panel to create or modify an existing page.\u003c/li\u003e\n\u003cli\u003eThe attacker embeds a malicious PHP callable string, such as \u003ccode\u003esystem('command')\u003c/code\u003e or \u003ccode\u003eexec('command')\u003c/code\u003e, within the page's frontmatter definition.\u003c/li\u003e\n\u003cli\u003eThe Grav application processes and stores the crafted page content, including the malicious callable directive.\u003c/li\u003e\n\u003cli\u003eAny user, whether authenticated or unauthenticated, navigates to and accesses the compromised Grav page via the web server.\u003c/li\u003e\n\u003cli\u003eDuring page rendering, the vulnerable \u003ccode\u003eBlueprint::dynamicData()\u003c/code\u003e function processes the page's frontmatter.\u003c/li\u003e\n\u003cli\u003eThe function passes the attacker-controlled callable string and its arguments directly to \u003ccode\u003ecall_user_func_array()\u003c/code\u003e without any sanitization or validation.\u003c/li\u003e\n\u003cli\u003eThe malicious PHP code executes on the underlying web server with the privileges of the web-server user, granting the attacker arbitrary remote code execution capabilities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65008 results in arbitrary remote code execution on the Grav host, with the privileges of the web-server user. This critical vulnerability (CVSS v3.1 Base Score: 9.8) grants attackers full control over the compromised Grav instance and potentially the underlying server. Impact could include website defacement, data exfiltration, installation of backdoors, further network penetration, or use of the server for malicious activities such as hosting malware or launching attacks. While no specific victim numbers or targeted sectors are detailed, any organization using affected Grav versions is at severe risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Grav to version 2.0.7 or later immediately to remediate CVE-2026-65008.\u003c/li\u003e\n\u003cli\u003eRegularly review user permissions in Grav, especially those with \u003ccode\u003eadmin.pages\u003c/code\u003e or \u003ccode\u003eapi.pages.write\u003c/code\u003e, to ensure the principle of least privilege is strictly enforced.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for unusual POST or PUT requests to Grav administration endpoints that create or modify page content, looking for suspicious embedded callable functions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T12:21:53Z","date_published":"2026-07-21T12:21:53Z","id":"https://feed.craftedsignal.io/briefs/2026-07-grav-rce/","summary":"A critical remote code execution vulnerability (CVE-2026-65008) in Grav versions prior to 2.0.7 allows an authenticated attacker with `admin.pages` or `api.pages.write` permissions to embed malicious callable directives in a page's frontmatter, leading to arbitrary code execution as the web-server user when the page is accessed.","title":"Grav Remote Code Execution Vulnerability in Blueprint::dynamicData()","url":"https://feed.craftedsignal.io/briefs/2026-07-grav-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Grav \u003c 2.0.7","version":"https://jsonfeed.org/version/1.1"}