CVE-2026-42607
critical
CVSS v3
9.1
CVSS v2
—
VIR risk
10.0
Description
Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
Predictions
Exploit likelihood
100%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Exploits
Exploit-DB
- EDB-52578 · webapps · php
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | getgrav/grav | <2.0.0-beta.2 | 2.0.0-beta.2 |
| COMPOSER | getgrav/grav | < 2.0.0-beta.2 | 2.0.0-beta.2 |
References
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.