GHSA-ggph-mfjj-69jrHighCVSS 8.8

Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability...

Published
September 4, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (1)

📋 Description

Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining denylist misses spl_autoload, which performs a PHP include. An authenticated user with only page-write rights (admin.pages or api.pages.write) can supply a crafted payload (e.g., via form frontmatter rendered by the Email plugin) that invokes spl_autoload through the sort filter, resulting in arbitrary PHP execution as the web server user.

🔗 References (4)