THREAT OPS › Threat News › [GHSA] GHSA-fj2p-qj2f-74v5 (high) — Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
[GHSA] GHSA-fj2p-qj2f-74v5 (high) — Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
GHSA-fj2p-qj2f-74v5 Severity: high CVE: CVE-2026-64850
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
### Summary An account with the `admin.pages` permission (or `api.pages.write`) can run shell commands on the server. The command executes whenever anyone — including an unauthenticated visitor — opens the page.
### Details `Blueprint::dynamicData()` (system/s
Indicators of compromise
- CVE-2026-64850cve
Original source: https://github.com/advisories/GHSA-fj2p-qj2f-74v5