CVE-2025-50286Exploit(getgrav / grav)

MEDIUMCVSS 8.1 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch getgrav grav systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grav

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
grav

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-03: 2PoC Mentioned / Linked · 2026-04-03: 1Exploit Tool / Code · 2026-04-03: 2Patch / Workaround · 2026-04-03: 1Technical Details · 2026-04-03: 204-03
Signal classification1 categories
Exploit
2100.0%
Referenced assets6 URLs
Full discourse2 posts
  • Metasploit Project@metasploit
    Exploit

    Metasploit Framework is here with 5 new modules! Exploits for FreeScout (CVE-2026-28289) and Grav CMS (CVE-2025-50286) RCEs, plus a generic HTTP command execution module and a new Windows persistence technique. We also have a slew of bug fixes and enhancements including SOCKS proxy performance improvements #Metasploit https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-03-2026/1

    Post summary

    Rapid7’s Metasploit release introduces new exploit modules for CVE‑2026‑28289 and CVE‑2025‑50286, offering RCE capabilities, but there is no evidence of current exploitation in the wild.

    11003586.3K
    253.3K followersView on X
  • Syed Aquib@syedaquib77
    Exploit

    📡 Strategic Insight: Metasploit Wrap-Up 04/03/2026 📅 Context: Rapid7 released Metasploit Framework 6.4.125 on 2026-04-03; adds five new modules including FreeScout unauthenticated RCE, Grav CMS plugin-upload RCE (CVE-2025-50286), generic multi/http/os_cmd_exec, Windows HKCU\Environment\UserInitMprLogonScript persistence, and new HTTP/HTTPS CMD payload adapters for Windows x86/x64. Also removes legacy modules, improves docs and fixes crashes/warnings. 📌 Key Takeaways: - New exploit modules: unauthenticated RCE for FreeScout; authenticated plugin-upload RCE for Grav CMS (CVE-2025-50286). Prioritize patching and hardening. - Generic multi/http/os_cmd_exec expands ability to target HTTP endpoints that lead to OS command execution; review input handling and detect command-exec patterns. - Windows persistence via HKCU\Environment\UserInitMprLogonScript runs payloads at interactive logon; monitor and alert on changes to that registry value and related logon artifacts. - HTTP/HTTPS CMD payload adapters for Windows x86/x64 expand delivery options; tune network detection for anomalous fetch patterns and unexpected GET/POSTs. - Quality/reliability improvements make these tools more usable; defenders should assume higher reliability in adversary emulation. 📝 Summary: This Metasploit update lowers the bar for exploiting plugin upload and HTTP-based command exec vectors and introduces a user-logon persistence trick, increasing the need for targeted detection and patching. 🛡️ Actionable Recommendations: - Update authorized assessment tooling (msfupdate or latest repo) to obtain new modules for testing. - Patch FreeScout and Grav instances, and restrict and harden plugin upload and install endpoints. - Audit webapps for unsafe eval or exec patterns and enforce input validation and least-privilege execution contexts. - Monitor and alert on writes or unexpected values for HKCU\Environment\UserInitMprLogonScript and related logon activity. - Update IDS and endpoint rules to flag behaviors introduced by multi/http/os_cmd_exec and the CMD payload fetch adapters. - Tune network detection for command payload fetches over HTTP/HTTPS and anomalous endpoint fetches. 🔗 Related Resources: - https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-03-2026 - https://github.com/rapid7/metasploit-framework/compare/6.4.124...6.4.125 - https://github.com/rapid7/metasploit-framework/pull/21069 - https://github.com/rapid7/metasploit-framework/pull/21029 - https://github.com/rapid7/metasploit-framework/pull/21172 🏷 Tags: #Metasploit #Exploitation #RCE #Persistence #Payloads #Penetration-Testing #Threat-Hunting #Security-Updates #CyberSecurity

    Post summary

    Metasploit 6.4.125 introduces functional exploit modules that lower the barrier for exploiting RCEs in FreeScout and Grav CMS, along with new persistence and command‑execution capabilities, highlighting an expanded attacker toolkit.

    00000299
    276 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetgravgrav1.7.48--

Explore more