PT-2026-94240 · Grav · Grav

·

CVE-2026-92917

·

Published

2026-09-17

·

Updated

2026-09-19

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions 2.0.0-rc.1 through 2.0.21
Description The Twig content sandbox fails to restrict dump and serialize filters, specifically print r, vardump, json encode, yaml encode, and string. This occurs because the GravExtension::assertSandboxDumpSafe() function calls SandboxExtension::isSandboxed() without a Source argument, which only reports a global sandbox flag that is never enabled. Consequently, an authenticated user with page-edit rights can use Twig processing in page content to dump the entire merged configuration. This bypasses path redaction in the SandboxConfig facade and exposes sensitive plugin secrets, including SMTP credentials, API tokens, webhook secrets, and cache backend passwords.
Recommendations Update Grav to version 2.0.22.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92917
GHSA-RFR9-7H4P-GX2X

Affected Products

Grav