Skip to content
archivevulnerability · 18 Aug 2026 · 12:19 UTC

CVE-2026-75827: Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic

VULNCVE-2026-75827source · GTH
HIGHCritical vulnerability — CVSS 8.8
What to do
  • Critical severity — schedule an urgent patch.

last 60 dispatches · spectrum

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected