๐Ÿ” CVE Alert

CVE-2026-64850

UNKNOWN 0.0

Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous callback parameters. An account with admin.pages or api.pages.write can use Grav\Common\Utils::arrayFilterRecursive() as a trampoline with system as the callback, place a command in page frontmatter, and execute that command as the web server user when the page is viewed. This issue is fixed in version 2.0.7.

CWE CWE-94
Vendor getgrav
Product grav
Published Aug 19, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for getgrav grav

Be the first to know when new unknown vulnerabilities affecting getgrav grav are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

getgrav / grav
< 2.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/getgrav/grav/security/advisories/GHSA-fj2p-qj2f-74v5 github.com: https://github.com/getgrav/grav/commit/acffa34cbb0787fee87c609e0d6289e904fee33c github.com: https://github.com/getgrav/grav/releases/tag/2.0.7