Warning: Critical vulnerability in Grav allows arbitrary command execution, Patch immediately!
ID: 5759a495-ab39-51fd-b478-65e2189f31aa
STIX ID: report--5759a495-ab39-51fd-b478-65e2189f31aa
Feed Name: CCB Advisories Feed
Threat Score
CVE-2025-66294 is a Server-Side Template Injection (SSTI) vulnerability affecting Grav versions prior to 1.8.0-beta.27 (CVSS 8.7) that can allow command execution via a vulnerable editor form; the advisory urges immediate patching, increased monitoring/detection, and notes potential for full system compromise if exploited.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
