Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-75827 — Proof-of-concept and lab for CVE-2026-75827, a Grav arbitrary file write via Blueprint dynamic-data error_log, with reproduction script and Docker lab. | Kitploit
उपकरण/GitHubGitHub/abraxas/cve-2026-75827
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubabraxas/cve-2026-75827

CVE-2026-75827

Proof-of-concept and lab for CVE-2026-75827, a Grav arbitrary file write via Blueprint dynamic-data error_log, with reproduction script and Docker lab.

रिपॉजिटरी देखें
218 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Abraxas Labs - CVE-2026-75827

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-75827

CVE-2026-75827

Grav 2.0.13 - getgrav

I am @abraxas_null. Loopback lab. The client is CVE-2026-75827-Abraxas-Labs.py.

The denylist missed error_log. Grav through 2.0.14 allowlists Class::method dynamic-data providers and denylists bare functions. A page-edit account plants a Form blueprint data-options@ directive. GET of that public form runs call_user_func_array on a bare PHP function. error_log type 3 appends attacker bytes to an attacker path. Then GET the file. Confirmed on tag 2.0.13. Patched in 2.0.15. This is not an upload action=.

CVECVE-2026-75827 · CVE.org
CWECWE-94
CVSSHigh: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ProductGrav
Affectedall versions through 2.0.13 (inclusive)
Patched2.0.15 and later
Authauthenticated (page-edit)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Someone with page-edit or blueprint-config plants data-options@: ['error_log', payload, 3, web-path]. A later GET of that form appends the payload. Point the path at a web-accessible .php and it is RCE. The lab stops at a unique string in poc-witness.txt. It is not unauthenticated RCE from a cold site.


How I found it

The GHSA named the denylist hole. I read isSafeDynamicCall, then Utils::isDangerousFunction, then the Form page. error_log is not on the list. The Class::method half already used a positive allowlist after GHSA-7pgq. The bare-function half did not.

Plant, then GET. The fixture page is already in the lab tree. GET /poc-form. Grav builds the form, hits dynamicData, calls error_log. Then GET /poc-witness.txt. Unique string, not a homepage, not a 404. Multiple GETs of the form append.

Wrong turns that already cost time: treating this as an upload action=; treating the form 200 as the proof (still Grav theme); treating Composer yelling about PHP 8.2 as a miss (the write still landed); putting system() in the message. The second GET is the tell.


The lab

Port 8088. Grav 2.0.13 admin skeleton, Form plugin on, web root writable. PHP 8.2 image is fine; Composer will complain.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml
  • lab/php-lab.ini

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-75827-Abraxas-Labs.py

Witness: GET /poc-witness.txt body contains POCWitness75827. Home HTML or empty 404 is not it.

Ways to lose without learning anything:

  • generic 200 Grav home HTML without the witness file
  • 404 poc-witness.txt
  • reverse shell or outbound connect
  • system() / exec() PHP payload

The fix

Update Grav to 2.0.15 or newer. Re-run CVE-2026-75827-Abraxas-Labs.py against the patched build: POCWitness75827 must not appear.


References

  • CVE-2026-75827 · NVD

  • CVE-2026-75827 · CVE.org

  • github.com/getgrav/grav/security/advisories/GHSA-f8wv-xp27-6gq7

  • www.vulncheck.com/advisories/grav-before-arbitrary-file-write-via-error-log

  • github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75827.json

  • nvd.nist.gov/vuln/detail/CVE-2026-75827

  • github.com/advisories/GHSA-f8wv-xp27-6gq7

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

टूल डाउनलोड करें