This advisory has been withdrawn because it is a duplicate of GHSA-f8wv-xp27-6gq7. This link is maintained to preserve external references.
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.
{
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T20:43:50Z",
"nvd_published_at": "2026-08-18T12:19:32Z",
"severity": "CRITICAL"
}