PT-2026-81149 · Grav · Grav
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.16
Description
An incomplete default denylist in the Twig sandbox configuration allows users with page-edit permissions to access system configuration secrets. When
config access is enabled, an attacker can use the config.get() or config.toArray() functions within Twig templates to retrieve sensitive information, such as the system.cache.redis.password variable.Recommendations
Update Grav to version 2.0.16 or later.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav