Skip to content

Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI blocklist bypass

Critical severity GitHub Reviewed Published Apr 27, 2026 in getgrav/grav • Updated May 5, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts