GHSA-crrc-vpp2-f5x7High· 7.5▾ TwilightDuplicate Advisory: Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-xjw5-q542-3vmr. This link is maintained to preserve external references.
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.
getgrav/grav < 2.0.16Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76846High· 7.5Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
GHSA-8vp7-8q4w-vv7mHigh· 6.5Duplicate Advisory: Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
CVE-2026-76839High· 7.7Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
CVE-2026-55885Medium· 6.8Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
GHSA-32fw-h446-j4hhHigh· 6.5Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
CVE-2026-56701Medium· 6.5Grav is Vulnerable to XXE via SVG Upload