THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7pgq-cr25-xvc8 (high) — Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

[GHSA] GHSA-7pgq-cr25-xvc8 (high) — Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

highgithub_advisoriesPublished 2026-09-17

GHSA-7pgq-cr25-xvc8 Severity: high CVE: CVE-2026-69088

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

### Summary Grav CMS's blueprint dynamic-field callable guard can be bypassed with a fully-qualified `Class::method` string, letting an account with only page-editing rights (`admin.pages`, not super-admin) plant a d

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7pgq-cr25-xvc8