Impact
The Grav Email plugin renders user‑controlled email body parameters as unsandboxed Twig templates (CWE-1336). An authenticated remote user holding only api.access and api.pages.write permissions can embed a Twig expression in the email body, publish the page, and trigger execution of arbitrary operating‑system commands as the PHP process user.
Affected Systems
The vulnerability affects the Grav CMS (getgrav:grav) before version 4.2.2. All installations running the Grav 4.x series with the email plugin enabled and without a patched version are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS is not available, and the issue is not listed in CISA KEV, suggesting no confirmed widespread exploitation. However, the RCE impact combined with the limited permissions required renders it a significant threat. The likely attack vector is remote, with the attacker interacting with the web interface or API to submit the manipulated form.
OpenCVE Enrichment