GHSA-f8wv-xp27-6gq7: Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
criticalvulnerability
security
Summary
Grav (a CMS platform) has a vulnerability in how it validates dynamic function calls in blueprints (configuration templates). The validation uses a denylist (a list of forbidden functions) for bare PHP functions, but `error_log` is missing from that list. An attacker with page-editing permissions can exploit this to write arbitrary PHP code to a file using `error_log`, then execute it for remote code execution (RCE, where an attacker runs commands on a system they don't own).
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.8%
Patch Available
Yes
Disclosure Date
September 17, 2026
Classification
Attack SophisticationModerate
Affected Packages
getgrav/grav@<= 2.0.14 (fixed: 2.0.15)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-f8wv-xp27-6gq7
First tracked: September 17, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 95%