PT-2026-99339 · Grav · Grav
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions 2.0.0 through 2.0.24
Description
A Twig content sandbox escape exists where the
array filter is included in the sandbox allowlist without the necessary needs is sandboxed guard. This allows the filter to call toArray() or perform an (array) cast without verifying the sandbox method allowlist. Since the grav Twig global acts as a Pimple-based dependency injection container (a tool used to manage object instantiation and dependencies), an attacker capable of authoring Twig in page content can use grav|array to access the container's private $values array. This process can expose the un-redacted Config service and the entire configuration tree, disclosing sensitive data such as plugin credentials, SMTP and OAuth secrets, Redis passwords, proxy URLs, and the security.* subtree. The exposed information is then rendered to anonymous visitors.Recommendations
Update to version 2.0.25.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav