CVE-2026-75827: Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic
HIGHCritical vulnerability — CVSS 8.8
What to do
- Critical severity — schedule an urgent patch.
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.
CVE · detail
- CVE-2026-75827nvd ↗EPSS 0.78%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected