Description
Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determines sandbox state by calling SandboxExtension::isSandboxed() without a Source argument, which reports only the global sandbox flag that Grav never enables, so the guard added in GHSA-mc5q-6hpj-rp7j never executes. As a result, an authenticated user with page-edit rights can render {{ config|print_r }} in page content with Twig processing enabled and dump Grav's entire merged configuration — print_r reflects the real Config object held in a private property of the SandboxConfig facade, bypassing its path redaction — exposing plugin secrets such as SMTP credentials, API tokens, webhook secrets and cache backend passwords. Grav 1.7 is not affected because it ships no Twig content sandbox. The issue is fixed in 2.0.22, where the affected filters are registered with Twig's needs_is_sandboxed flag.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a failure in Grav's Twig sandbox to limit the use of certain filters such as print_r when the source argument is omitted. An authenticated editor can embed a template tag that causes Grav to dump its entire merged configuration. The exposed data includes SMTP credentials, API tokens, webhook secrets, and cache passwords. This results in a full disclosure of sensitive storage data, represented by CWE‑200.

Affected Systems

The affected product is the Grav flat‑file CMS provided by getgrav. Versions 2.0.0‑rc.1 through 2.0.21 are vulnerable, while the older 1.7 series is not. The issue is fixed in Grav 2.0.22 and later releases. The vulnerability affects any instance that deploys these versions and allows users with page‑edit permissions to render arbitrary Twig content.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the vulnerability is exploitable by any user who has legitimate page‑edit access, making it a privileged internal threat. The EPSS score is not available, but the lack of listing in CISA KEV suggests it has not yet been widely exploited. Attackers can obtain configuration secrets that may grant further system compromise. The vector is confined to authenticated users with editing rights, though the impact on data confidentiality is extensive.

Generated by OpenCVE AI on September 18, 2026 at 06:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Grav CMS to version 2.0.22 or later, where the Twig sandbox filters are correctly guarded.
  • Limit the use of configuration‑dumping filters (print_r, vardump, json_encode, yaml_encode, string) in page templates, or temporarily remove these filters from the Twig environment via configuration.
  • Revise user roles to ensure only trusted personnel have page‑edit permissions, and review existing editors for least‑privilege compliance.

Generated by OpenCVE AI on September 18, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determines sandbox state by calling SandboxExtension::isSandboxed() without a Source argument, which reports only the global sandbox flag that Grav never enables, so the guard added in GHSA-mc5q-6hpj-rp7j never executes. As a result, an authenticated user with page-edit rights can render {{ config|print_r }} in page content with Twig processing enabled and dump Grav's entire merged configuration — print_r reflects the real Config object held in a private property of the SandboxConfig facade, bypassing its path redaction — exposing plugin secrets such as SMTP credentials, API tokens, webhook secrets and cache backend passwords. Grav 1.7 is not affected because it ships no Twig content sandbox. The issue is fixed in 2.0.22, where the affected filters are registered with Twig's needs_is_sandboxed flag.
Title Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r
First Time appeared Getgrav
Getgrav grav
Weaknesses CWE-200
CPEs cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
Vendors & Products Getgrav
Getgrav grav
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:16:41.341Z

Reserved: 2026-09-17T11:07:29.772Z

Link: CVE-2026-92917

cve-icon Vulnrichment

Updated: 2026-09-19T02:16:33.479Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:30.907

Modified: 2026-09-19T03:17:18.167

Link: CVE-2026-92917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor