| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j274-39qw-32c9 | Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray() |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 14 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta1:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta4:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:rc1:*:*:*:*:*:* |
Mon, 11 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgrav
Getgrav grav |
|
| Vendors & Products |
Getgrav
Getgrav grav |
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all plugin secrets (SMTP passwords, AWS keys, OAuth client secrets, API tokens) — into the rendered HTML. No administrator privileges are required. This vulnerability is fixed in 2.0.0-rc.2. | |
| Title | Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray() | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T18:06:17.679Z
Reserved: 2026-05-07T18:04:17.310Z
Link: CVE-2026-44738
Updated: 2026-05-14T18:03:19.535Z
Status : Modified
Published: 2026-05-11T17:16:34.747
Modified: 2026-05-14T18:16:50.440
Link: CVE-2026-44738
No data.
OpenCVE Enrichment
Updated: 2026-05-13T21:15:04Z
Github GHSA