Skip to content
archivevulnerability · 17 Sep 2026 · 17:15 UTC

GHSA-c4wf-2xxc-68qm: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

VULNCVE-2026-65608source · GTH
HIGHHigh-risk vulnerability — CVSS 8.8

last 60 dispatches · spectrum

### Summary A missing validation check in Grav's Flex framework lets an account holding nothing but an ordinary object-create permission on a single Flex directory execute arbitrary shell commands on the server. Any authenticated user with `create` or `update` rights on a Flex-based directory (Flex Users, Flex Pages, Flex Objects, or any custom Flex type) can trigger it the moment a blueprint field anywhere in that directory carries a `data-*@:` directive, since the code that resolves those directives calls `call_user_func_array()` on attacker-influenced input with no restriction at all. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected