PT-2026-94240 · Grav · Grav
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions 2.0.0-rc.1 through 2.0.21
Description
The Twig content sandbox fails to restrict dump and serialize filters, specifically
print r, vardump, json encode, yaml encode, and string. This occurs because the GravExtension::assertSandboxDumpSafe() function calls SandboxExtension::isSandboxed() without a Source argument, which only reports a global sandbox flag that is never enabled. Consequently, an authenticated user with page-edit rights can use Twig processing in page content to dump the entire merged configuration. This bypasses path redaction in the SandboxConfig facade and exposes sensitive plugin secrets, including SMTP credentials, API tokens, webhook secrets, and cache backend passwords.Recommendations
Update Grav to version 2.0.22.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav