THREAT OPS › Threat News › [GHSA] GHSA-c4wf-2xxc-68qm (high) — Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
[GHSA] GHSA-c4wf-2xxc-68qm (high) — Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
GHSA-c4wf-2xxc-68qm Severity: high CVE: CVE-2026-65608
Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
### Summary
A missing validation check in Grav's Flex framework lets an account holding nothing but an ordinary object-create permission on a single Flex directory execute arbitrary shell commands on the server. Any authenticated user
Indicators of compromise
- fae9e1bf2c40ce0b50d0dfce647aaa1d22f98969sha1
- CVE-2026-65608cve
Original source: https://github.com/advisories/GHSA-c4wf-2xxc-68qm