THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r94f-hx44-8jqf (high) — Grav CMS vulnerable to remote code execution via .zip file upload

[GHSA] GHSA-r94f-hx44-8jqf (high) — Grav CMS vulnerable to remote code execution via .zip file upload

highgithub_advisoriesPublished 2026-09-17

GHSA-r94f-hx44-8jqf Severity: high CVE: CVE-2026-72819

Grav CMS vulnerable to remote code execution via .zip file upload

### Summary

A logged-in user can run any command on the server. A settings field can fill itself by calling one of Grav's built-in routines, and a safety check is supposed to allow only harmless ones. The check only recognises a routine when its name is written as one piece o

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r94f-hx44-8jqf