THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fj2p-qj2f-74v5 (high) — Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()

[GHSA] GHSA-fj2p-qj2f-74v5 (high) — Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()

medgithub_advisoriesPublished 2026-09-02

GHSA-fj2p-qj2f-74v5 Severity: high CVE: CVE-2026-64850

Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()

### Summary An account with the `admin.pages` permission (or `api.pages.write`) can run shell commands on the server. The command executes whenever anyone — including an unauthenticated visitor — opens the page.

### Details `Blueprint::dynamicData()` (system/s

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fj2p-qj2f-74v5