Executive brief
Grav CMS, a popular open-source content management system, contains a vulnerability in how it handles cached data. If an attacker can modify or place a malicious file in the server's cache directory, they can trigger the execution of unauthorized code when the system attempts to read that data. This could lead to a full takeover of the website or access to sensitive server information.
Technical details
An insecure deserialization vulnerability exists in Grav CMS within the `FileCache::doGet` method of `system/src/Grav/Framework/Cache/Adapter/FileCache.php`. The component uses `unserialize()` with `['allowed_classes' => true]`, which permits the instantiation of arbitrary PHP objects. If an attacker can achieve cache poisoning (e.g., via insecure directory permissions or other file-write primitives), they can provide a malicious serialized payload. When the application retrieves this cache entry, it triggers PHP magic methods (like `__wakeup` or `__destruct`), which can be leveraged via gadget chains (e.g., Monolog, Laravel, or Symfony) to achieve remote code execution. The fix introduces HMAC-SHA256 signing for all cache payloads to ensure integrity before deserialization.
Affected products
- Trilby Media Grav CMS >= 1.7.44, <= 1.7.49.5, 2.0.0-beta.1
Timeline
- 2026-04-23: patched: Fix committed to repository (c66dfeb5f)
- 2026-04-27: advisory: GitHub Security Advisory GHSA-gwfr-jfjf-92vv published
- 2026-04-28: disclosed: CVE-2026-7317 published