CVE-2026-64850 | getgrav Grav up to 2.0.6 Blueprint Blueprint.php Blueprint::dynamicData os command injection

SecurityVulns

A vulnerability marked as problematic has been reported in getgrav Grav up to 2.0.6. This vulnerability affects the function Blueprint::dynamicData of the file system/src/Grav/Common/Data/Blueprint.php of the component Blueprint. This manipulation causes os command injection.

This vulnerability is tracked as CVE-2026-64850. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More