PT-2026-94239 · Grav · Grav
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions 1.7.0 through 1.7.53.2
Grav versions 2.0.0 through 2.0.21
Description
When the debugger is enabled via
system.debugger.enabled: true, the Clockwork profiler endpoint is exposed without authentication. The InitializeProcessor::handleDebuggerRequest() function intercepts paths containing the '/ clockwork/' endpoint and passes them to Debugger::debuggerRequest(), which fails to perform user lookups, IP restrictions, or authenticator checks. This allows anonymous pagination over the stored history. By default, records may contain raw request cookies, including session cookies that allow session hijacking of authenticated administrators. Additionally, the full parsed request body is stored, leading to plaintext exposure of data[username] and data[password] because the password filter only inspects top-level keys. The system also exposes site configurations, SMTP credentials, third-party API keys, and license keys. Authorization and X-API-Token headers remain stored even when the censored option is enabled. In version 2.0, using the provider: debugbar setting does not mitigate this as the Clockwork provider is forced for requests preferring JSON responses.Recommendations
Update Grav versions 1.7.0 through 1.7.53.2 to version 1.7.53.4.
Update Grav versions 2.0.0 through 2.0.21 to version 2.0.22.
Set
system.debugger.enabled to false.
Block access to the '/ clockwork/' endpoint at the web server or CDN level.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav