PT-2026-70197 · Craft Cms · Craft Cms
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions 5.0.0-RC1 through 5.10.5
Craft CMS versions 4.0.0-RC1 through 4.18.1
Description
An arbitrary file read issue exists where the
create() Twig function fails to include SplFileObject in its class instantiation blocklist. This allows an authenticated administrator with allowAdminChanges=true to configure a malicious entry type title or URI format that instantiates SplFileObject within a non-sandboxed template context. Consequently, when a user creates an entry in the affected section, sensitive server files, such as the .env file containing security keys and database credentials, can be read and rendered as entry titles.Recommendations
Update Craft CMS versions 5.0.0-RC1 through 5.10.5 to version 5.10.6.
Update Craft CMS versions 4.0.0-RC1 through 4.18.1 to version 4.18.2.
Exploit
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms