THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c4wf-2xxc-68qm (high) — Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

[GHSA] GHSA-c4wf-2xxc-68qm (high) — Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

highgithub_advisoriesPublished 2026-09-17

GHSA-c4wf-2xxc-68qm Severity: high CVE: CVE-2026-65608

Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

### Summary

A missing validation check in Grav's Flex framework lets an account holding nothing but an ordinary object-create permission on a single Flex directory execute arbitrary shell commands on the server. Any authenticated user

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c4wf-2xxc-68qm