CVE-2026-64850: Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
An account with the admin.pages permission (or api.pages.write) can run shell
commands on the server. The command executes whenever anyone — including an
unauthenticated visitor — opens the page.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-64850 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →