CVE-2026-65608 PUBLISHED

Grav before 2.0.9 Remote Code Execution via FlexDirectory

Assigner: VulnCheck
Reserved: 22.07.2026 Published: 23.07.2026 Updated: 23.07.2026

Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registers this handler for every Flex directory, it bypasses the validation added to Blueprint::dynamicData() in 2.0.7 (GHSA-fj2p-qj2f-74v5). Any authenticated user with create or update permission on any Flex-based directory (Flex Users, Flex Pages, Flex Objects, or custom Flex types) can execute arbitrary shell commands on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor getgrav
Product grav
Versions Default: unaffected
  • affected from 1.7.0 to 2.0.9 (excl.)
  • Version 2.0.9 is unaffected

Credits

  • haftoe reporter

References

Problem Types

  • Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') CWE