CyberRota Analysis
AI-GeneratedThe getgrav/grav-plugin-api plugin prior to version 1.0.13 is vulnerable due to insufficient validation of API key scopes, allowing attackers with minimal-scope API keys to create unscoped super keys. This critical flaw can lead to unauthorized access and potential remote code execution, as attackers can bypass scope restrictions entirely. Organizations using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access scope, and the new key's scopes are read directly from the request body with no subset check. An attacker holding a minimal-scope API key on a super account can submit an empty scopes array to mint an unscoped, full-access super key, bypassing scope restrictions (and enabling further chains such as configuration write to RCE).