Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its...

zetlyn/cve-ghsa vulnerability ghsa GHSA-g565-6qmq-w49v cve CVE-2026-100668 known 2026-09-26

https://github.com/advisories/GHSA-g565-6qmq-w49v

Properties

cvss6.5
receipt
Source
GitHub advisories
Said since
2026-09-27 10:07 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

cweCWE-200
receipt
Source
GitHub advisories
Said since
2026-09-27 10:07 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

severityhigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Said since
2026-09-27 10:07 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

Text

Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its... Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is registered without the needs_is_sandboxed guard that print_r, vardump, json_encode, yaml_encode and string carry, and its implementation calls toArray() — or falls back to an (array) cast — without consulting the sandbox method allowlist. Because the `grav` Twig global is the raw Pimple-based dependency injection container, a user who can author Twig in page content can evaluate `grav|array` to read the container's private $values array, including the un-redacted Config service; a second array cast returns the entire configuration tree, disclosing plugin credentials, SMTP and OAuth secrets, Redis passwords, proxy URLs and the security.* subtree that the sandbox's redaction is meant to hide. Because the payload is stored in page content, the disclosed configuration is rendered to anonymous visitors. Grav 1.7 is not affected as it has no Twig content sandbox. Fixed in Grav 2.0.25.