PT-2026-76929 · Grav · Grav-Plugin-Api
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
grav-plugin-api versions prior to 1.0.15
Description
Insufficient validation of Twig content in the 'translate()' endpoint allows users with
api.pages.write permission to persist pages with process.twig enabled. By submitting crafted header and content parameters, an attacker can perform server-side template injection, where malicious payloads are executed during the rendering process.Recommendations
Update grav-plugin-api to version 1.0.15 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav-Plugin-Api