PT-2026-99339 · Grav · Grav

·

CVE-2026-100668

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions 2.0.0 through 2.0.24
Description A Twig content sandbox escape exists where the array filter is included in the sandbox allowlist without the necessary needs is sandboxed guard. This allows the filter to call toArray() or perform an (array) cast without verifying the sandbox method allowlist. Since the grav Twig global acts as a Pimple-based dependency injection container (a tool used to manage object instantiation and dependencies), an attacker capable of authoring Twig in page content can use grav|array to access the container's private $values array. This process can expose the un-redacted Config service and the entire configuration tree, disclosing sensitive data such as plugin credentials, SMTP and OAuth secrets, Redis passwords, proxy URLs, and the security.* subtree. The exposed information is then rendered to anonymous visitors.
Recommendations Update to version 2.0.25.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100668
GHSA-59QM-58V5-GVC5

Affected Products

Grav