CVE-2025-50286 is a remote code execution vulnerability in Grav CMS v1.7.48. According to the provided content, an authenticated administrator can use the /admin/tools/direct-install interface to upload a malicious plugin. The uploaded plugin is then automatically extracted and loaded by the application, resulting in execution of attacker-controlled PHP code. The issue is effectively an unsafe extension upload and installation path that permits arbitrary code to be introduced and executed through the plugin mechanism.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a Metasploit exploit module for CVE-2025-50286 targeting Grav CMS Admin Plugin's Direct Install feature. Structure: (1) `grav_admin_direct_install_rce_cve_2025_50286.rb` is the primary Ruby Metasploit module; (2) `docs/grav_admin_direct_install_rce_cve_2025_50286.md` provides vulnerability background, affected/tested versions, and msfconsole usage; (3) `docker_setup/setup.sh` is a helper script to install PHP extensions and enable Apache rewrite for a lab; plus README and license. Exploit flow/capabilities: The module uses `Msf::Exploit::Remote::HttpClient` with AutoCheck. It performs a Grav fingerprint by checking for Grav-specific HTML attributes on `/admin`, verifies the login form, then authenticates using admin credentials by extracting `login-nonce` and POSTing to `/admin` with `task=login`. After authentication it fetches `/admin` again to scrape `span.grav-version`. For exploitation it generates a random plugin name, builds a ZIP containing a Grav plugin whose `onPagesInitialized` handler executes `eval(base64_decode(<payload>))`, then uploads it via multipart/form-data POST to `/admin/tools/direct-install` using an extracted `admin-nonce`. Successful installation causes Grav to load/execute the plugin PHP, yielding arbitrary code execution (typically a reverse Meterpreter session) as the web server user. The module includes a post-session cleanup routine that runs `rm -rf user/plugins/<random>plugin` on the target to remove artifacts. Notable targeting details: Authenticated RCE only (requires valid admin creds). Tested against Grav CMS 1.7.48 / Admin Plugin 1.10.48; documentation claims 1.7.x / 1.10.x affected. Network endpoints of interest are `/admin` and `/admin/tools/direct-install`, and the on-disk plugin drop location under `user/plugins/`.
This repository provides a proof-of-concept exploit for CVE-2025-50286, targeting Grav CMS v1.7.48 with Admin Plugin v1.10.48. The exploit leverages the 'Direct Install' feature in the admin panel, which allows an authenticated administrator to upload a malicious plugin ZIP file. The provided plugin ('evilplugin') contains a PHP file that executes arbitrary system commands passed via the 'cmd' GET parameter. The README details the exploitation steps, including preparing a reverse shell listener, uploading the plugin, and triggering the payload via a crafted HTTP request. The repository includes the malicious plugin's PHP code and minimal YAML files required for plugin validation. The main attack vector is network-based, requiring admin access to the web interface. The exploit enables full remote code execution as the web server user, potentially leading to complete system compromise.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.