Junglewise Threat Intelligence

CVE-2026-7317: Trilby Media Grav CMS insecure deserialization in FileCache

CVE-2026-7317 · Severity: medium · CVSS 5 · Published 2026-04-28

Technologies: getgrav/grav (Packagist). Vendors: Packagist.

Executive brief

Grav CMS, a popular open-source content management system, contains a vulnerability in how it handles cached data. If an attacker can modify or place a malicious file in the server's cache directory, they can trigger the execution of unauthorized code when the system attempts to read that data. This could lead to a full takeover of the website or access to sensitive server information.

Technical details

An insecure deserialization vulnerability exists in Grav CMS within the `FileCache::doGet` method of `system/src/Grav/Framework/Cache/Adapter/FileCache.php`. The component uses `unserialize()` with `['allowed_classes' => true]`, which permits the instantiation of arbitrary PHP objects. If an attacker can achieve cache poisoning (e.g., via insecure directory permissions or other file-write primitives), they can provide a malicious serialized payload. When the application retrieves this cache entry, it triggers PHP magic methods (like `__wakeup` or `__destruct`), which can be leveraged via gadget chains (e.g., Monolog, Laravel, or Symfony) to achieve remote code execution. The fix introduces HMAC-SHA256 signing for all cache payloads to ensure integrity before deserialization.

Affected products

  • Trilby Media Grav CMS >= 1.7.44, <= 1.7.49.5, 2.0.0-beta.1

Timeline

  • 2026-04-23: patched: Fix committed to repository (c66dfeb5f)
  • 2026-04-27: advisory: GitHub Security Advisory GHSA-gwfr-jfjf-92vv published
  • 2026-04-28: disclosed: CVE-2026-7317 published

References

Related threats