OS Command Injection in Grav CMS - #VU130082

 

OS Command Injection in Grav CMS - #VU130082

Published: May 5, 2026


Vulnerability identifier: #VU130082
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands.

The vulnerability exists due to improper neutralization of special elements used in an os command in InstallCommand git clone handling when constructing a git clone command from branch, url, and path values. A remote user can supply specially crafted dependency values to execute arbitrary commands.

The vulnerable functionality is reachable through plugin or theme installation.


Affected software

Grav CMS

Remediation

Install security update from vendor's website.

Grav CMS - update to 2.0.0 beta.2

External References

Related Security Bulletins