logo

Warning: Critical vulnerability in Grav allows arbitrary command execution, Patch immediately!

ID: 5759a495-ab39-51fd-b478-65e2189f31aa

STIX ID: report--5759a495-ab39-51fd-b478-65e2189f31aa

Feed Name: CCB Advisories Feed

Threat Score
72/100

Date Published: 2025-12-02

Date Updated: 2026-07-24

...
...

CVE-2025-66294 is a Server-Side Template Injection (SSTI) vulnerability affecting Grav versions prior to 1.8.0-beta.27 (CVSS 8.7) that can allow command execution via a vulnerable editor form; the advisory urges immediate patching, increased monitoring/detection, and notes potential for full system compromise if exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.