GHSA-mw85-cjh9-8hp7High· 6.5▾ TwilightDuplicate Advisory: Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-p597-crqc-m349. This link is maintained to preserve external references.
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like cache credentials by using dot notation in Twig templates, bypassing the config_denied_paths restrictions.
getgrav/grav < 2.0.16Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-72698High· 6.5Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
CVE-2026-69088High· 8.1Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
CVE-2026-61842Medium· 6.5Grav is a file-based Web platform
CVE-2026-56701Medium· 6.5Grav is Vulnerable to XXE via SVG Upload
GHSA-32fw-h446-j4hhHigh· 6.5Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
CVE-2026-72697High· 6.5Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content