CVE-2026-44738
Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.page
Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration, including all plugin secrets (SMTP passwords, AWS keys, OAuth client secrets, API tokens), into the rendered HTML. No administrator privileges are required.
This vulnerability is fixed in 2.0.0-rc.2.
HIGH · CVSS 7.7
EPSS 0.00036
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0