Signal is active with 2 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection and, via a gadget chain, arbitrary code execution where an attacker controls the serialized input. Additionally, InstallCommand's git clone operation passes the branch, url, and path parameters into a shell command without escaping, allowing OS command injection via plugin/theme installation (which requires admin access). A Twig security blocklist bypass (server-side template injection) is also present. The issues are fixed in 2.0.0-beta.2.
CVE-2026-56700 is a critical code‑execution vulnerability in Grav CMS (pre‑2.0.0‑beta.2) due to unsafe unserialize() calls, with a patch now available.
🚨Critical - Grav CMS Multiple Remote Code Execution Vulnerabilities (CVE-2026-56700)
Grav CMS ships several code-execution flaws. The headline issue is PHP object injection: three unsafe unserialize() calls (in Scheduler\JobQueue, FileCache, and Session) deserialize untrusted data without restricting allowed classes. Where an attacker controls the serialized input, a gadget chain turns that into arbitrary code execution — and the CVSS vector indicates no privileges or user interaction required.
On top of that, the plugin/theme InstallCommand passes the branch, URL, and path into a git clone shell command without escaping, giving OS command injection (admin-only), and a Twig security blocklist bypass enables server-side template injection.
👉Upgrade to Grav 2.0.0-beta.2.
Post summary
The post alerts readers to multiple remote code‑execution vulnerabilities in Grav CMS, provides technical details, and recommends upgrading to Grav 2.0.0‑beta.2 to apply the fix.