Impact
The vulnerability arises from a failure in Grav's Twig sandbox to limit the use of certain filters such as print_r when the source argument is omitted. An authenticated editor can embed a template tag that causes Grav to dump its entire merged configuration. The exposed data includes SMTP credentials, API tokens, webhook secrets, and cache passwords. This results in a full disclosure of sensitive storage data, represented by CWE‑200.
Affected Systems
The affected product is the Grav flat‑file CMS provided by getgrav. Versions 2.0.0‑rc.1 through 2.0.21 are vulnerable, while the older 1.7 series is not. The issue is fixed in Grav 2.0.22 and later releases. The vulnerability affects any instance that deploys these versions and allows users with page‑edit permissions to render arbitrary Twig content.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the vulnerability is exploitable by any user who has legitimate page‑edit access, making it a privileged internal threat. The EPSS score is not available, but the lack of listing in CISA KEV suggests it has not yet been widely exploited. Attackers can obtain configuration secrets that may grant further system compromise. The vector is confined to authenticated users with editing rights, though the impact on data confidentiality is extensive.
OpenCVE Enrichment