{"id":"CVE-2026-65008","title":"Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func…","summary":"Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"getgrav","product":"grav","affected":["grav < 2.0.7"],"published":"2026-07-21","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:28.523","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-65008","references":[{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-fj2p-qj2f-74v5","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/grav-before-remote-code-execution-via-blueprint-dynamicdata","label":"disclosure@vulncheck.com"},{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-fj2p-qj2f-74v5","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-07-22T14:20:32.223632Z"},"epss":0.0249,"epssPercentile":0.84148,"exploits":{"exploitdb":true,"github":1,"githubRepos":["https://github.com/zer0dayf/CVE-2026-65008"],"checkedAt":"2026-10-08T16:52:49.772Z"},"ingestedAt":"2026-10-08T16:52:14.705Z","slug":"CVE-2026-65008","body":"## Overview\n\nGrav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because the form plugin routes page frontmatter through this path, an authenticated account with the admin.pages (or api.pages.write) permission can plant a malicious callable directive in a page. The command then executes as the web-server user whenever anyone — including an unauthenticated visitor — accesses the page.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.5,"exploitation":12,"ransomware":0},"changes":[]}