Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.con…
Critical CVSS 9.8
Summary
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/getgrav/grav/security/advisories/GHSA-2x29-3mjq-2pvx
- https://www.vulncheck.com/advisories/grav-api-plugin-before-rce-via-configcontroller-scope-bypass
Timeline
- nvd_ingest NVD