Skip to main content
Vulnerability Database/CVE-2026-100668

CVE-2026-100668: Grav CMS Information Disclosure Vulnerability

CVE-2026-100668 is an information disclosure flaw in Grav CMS that exposes sensitive configuration data through Twig sandbox escape. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-100668 Overview

CVE-2026-100668 is a Twig content sandbox escape in Grav versions 2.0.0 through 2.0.24. The array filter is on the sandbox allowlist but is registered without the needs_is_sandboxed guard that other serialization filters carry. An authenticated user with page authoring privileges can evaluate grav|array to coerce the raw Pimple dependency injection container into an array. The resulting dump exposes the un-redacted Config service, including plugin credentials, SMTP and OAuth secrets, Redis passwords, proxy URLs, and the security.* subtree. Because the payload is stored in page content, the configuration is rendered to anonymous visitors on every page view.

Critical Impact

Any Twig-authoring account can bypass the content sandbox and publish the full Grav configuration tree, including secrets, to unauthenticated site visitors.

Affected Products

  • Grav CMS 2.0.0 through 2.0.24
  • Grav installations exposing Twig content authoring to non-admin editors
  • Grav 1.7 is not affected because it has no Twig content sandbox

Discovery Timeline

  • 2026-09-26 - CVE-2026-100668 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100668

Vulnerability Analysis

Grav's Twig content sandbox restricts which filters, functions, and methods a page author can invoke inside stored Twig templates. The sandbox enforces this restriction by registering sensitive serialization helpers such as print_r, var_dump, json_encode, yaml_encode, and string with a needs_is_sandboxed guard. The guard forces the extension to consult the sandbox allowlist before dumping arbitrary objects.

The array filter and its identical function form were added to the allowlist without this guard. The filter's implementation calls toArray() on the target or falls back to a native (array) cast. Neither path consults the sandbox method allowlist. This information-disclosure flaw is tracked as [CWE-200].

Root Cause

The grav Twig global is the raw Pimple-based dependency injection container. A (array) cast on a Pimple container exposes its private $values array. Casting a second time returns the full configuration tree, including the Config service that the sandbox's redaction layer is designed to hide. The missing needs_is_sandboxed registration removes the gate that would otherwise block this operation.

Attack Vector

An authenticated editor publishes a page containing a Twig expression such as {{ grav|array|array }}. Grav renders the page and emits the container's internal state into the HTML response. Because the payload persists in page content, every subsequent anonymous request receives the leaked configuration, including SMTP, OAuth, Redis, and proxy credentials.

Technical details are available in the GitHub Security Advisory GHSA-59qm-58v5-gvc5 and the VulnCheck Advisory for Grav Sandbox Escape.

Detection Methods for CVE-2026-100668

Indicators of Compromise

  • Page content or stored Twig templates containing the |array filter applied to the grav global, or chained |array|array expressions.
  • Rendered HTML pages that contain configuration keys such as security, smtp, oauth, redis, or plugin credential fields.
  • Unexpected modifications to Markdown or Twig files under user/pages/ by non-administrative accounts.
  • Outbound requests to attacker-controlled hosts following exposure of OAuth or SMTP credentials.

Detection Strategies

  • Grep the pages tree for Twig filters referencing grav|array, config|array, or raw casts of framework globals.
  • Compare rendered page output against a baseline and alert on HTML containing serialized PHP array markers tied to Grav service names.
  • Review web server access logs for repeated anonymous requests to pages recently edited by low-privileged editor accounts.

Monitoring Recommendations

  • Enable audit logging on page create and edit actions and forward events to a central SIEM for correlation.
  • Monitor for new or rotated credentials appearing in response bodies using data loss prevention rules.
  • Track Grav version strings in HTTP responses and flag any instance still reporting a version earlier than 2.0.25.

How to Mitigate CVE-2026-100668

Immediate Actions Required

  • Upgrade Grav to version 2.0.25 or later on all production and staging sites.
  • Audit every page under user/pages/ for Twig expressions using the array filter against framework globals and remove them.
  • Rotate all secrets that may have been rendered, including SMTP, OAuth, Redis, proxy, and plugin API credentials.
  • Restrict Twig-in-content privileges to administrators until the upgrade is complete.

Patch Information

The Grav maintainers fixed the issue in version 2.0.25 by registering the array filter with the needs_is_sandboxed guard, aligning it with the other serialization helpers. Patch details are documented in the GitHub Security Advisory GHSA-59qm-58v5-gvc5.

Workarounds

  • Disable the Twig processing option on page frontmatter (process: twig: false) for all content authored by non-administrators.
  • Remove or restrict the editor role's ability to toggle Twig processing in the Grav Admin plugin configuration.
  • Place the site behind a web application firewall rule that blocks responses containing serialized Grav configuration keys.
bash
# Upgrade Grav using the bundled CLI updater
bin/gpm selfupgrade
bin/gpm update

# Verify the installed version is 2.0.25 or later
bin/grav --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.