Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-69088— Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint

CVSS 8.1 · High EPSS 0.23% · P14

Affected Version Matrix 2

VendorProductVersion RangeStatus
getgravgrav2.0.7< 2.0.11affected
2.0.11unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-69088

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint
Source: CVE Program / CVE List V5
Vulnerability Description
Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall() only applies its dangerous-callable denylist to strings that do not contain '::'. An account with only page-editing rights (admin.pages, not super-admin or admin.pages_twig) can plant a directive in a page's form-field frontmatter that invokes an arbitrary public static PHP method with attacker-controlled arguments. Using built-in gadget methods this allows reading of any server-readable file (disclosed to anonymous visitors of the crafted page) and arbitrary creation/copying of files and directories under the web-server account. Fixed in 2.0.11.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5
Vulnerability Title
getgrav grav 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
getgrav Grav是getgrav个人开发者开源的一款一套可扩展的内容管理系统。 getgrav grav 2.0.7版本至2.0.10版本存在代码注入漏洞,该漏洞源于Blueprint::isSafeDynamicCall()未正确验证完全限定的静态方法调用(Class::method),仅对不包含'::'的字符串应用危险可调用拒绝列表,导致具有页面编辑权限的账户可在页面表单字段frontmatter中植入指令,调用任意公共静态PHP方法,从而读取服务器可读文件并任意创建或复制文件和目录。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
getgravgrav 2.0.7 ~ 2.0.11 -

II. Public POCs for CVE-2026-69088

#POC DescriptionSource LinkShenlong Link
AI-Generated POCVerified env Premium
Reproduced successfully in a real sandbox· Below is the actual recording of building the environment and exploiting the vulnerability.
Success marker:VULNERABLE: Blueprint data-default@ invoked arbitrary static method; leaked /flag.txt token=PROOF_7fd13a7ff2abcf0a via \Symfony\Component\Yaml\Yaml::parseFile
Reproduction recording is a Pro+ exclusive
Watch the full sandbox build + live exploit recording for this CVE. Limited-time ¥499/mo.
Upgrade to Pro+
claude_code · 47665 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-69088

登录查看更多情报信息。

Vendor Advisories for CVE-2026-69088 (1)

Other References for CVE-2026-69088 (1)

Same Patch Batch · getgrav · 2026-08-03 · 3 CVEs total

CVE-2026-690897.5 HIGHGrav CMS before 2.0.11 Path Traversal via watermark
CVE-2026-690876.5 MEDIUMGrav Form Plugin before 9.1.13 Open Redirect via form.value() Twig

IV. Related Vulnerabilities

V. Comments for CVE-2026-69088

No comments yet


Leave a comment