GHSA-q6cm-x4f7-73r6CriticalCVSS 9.8

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController...

Published
August 14, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.

🔗 References (4)