THREAT OPS › Threat News › [GHSA] GHSA-7pgq-cr25-xvc8 (high) — Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
[GHSA] GHSA-7pgq-cr25-xvc8 (high) — Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
GHSA-7pgq-cr25-xvc8 Severity: high CVE: CVE-2026-69088
Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
### Summary Grav CMS's blueprint dynamic-field callable guard can be bypassed with a fully-qualified `Class::method` string, letting an account with only page-editing rights (`admin.pages`, not super-admin) plant a d
Indicators of compromise
- CVE-2026-69088cve
- https://grav.example`url
Original source: https://github.com/advisories/GHSA-7pgq-cr25-xvc8