Skip to main content
Vulnerability Database/CVE-2026-100671

CVE-2026-100671: Grav CMS Information Disclosure Flaw

CVE-2026-100671 is an information disclosure vulnerability in Grav CMS that allows session hijacking through cached Twig content. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-100671 Overview

Grav is a flat-file content management system (CMS) affected by an information disclosure vulnerability in its Twig sandbox. The vulnerability allows a low-privileged page-write user to steal administrator session cookies through the allowlisted get_cookie() function. Because get_cookie() reads cookies server-side via filter_input(INPUT_COOKIE, ...), the HttpOnly, Secure, and SameSite attributes provide no protection. Grav caches post-Twig output using only page identity and configuration checksum, with no session or user dimension, allowing the captured cookie to be served to unauthenticated visitors. The flaw is tracked under CWE-200.

Critical Impact

A page-write user can capture an administrator's session cookie and have Grav cache it, allowing any unauthenticated visitor to replay the cookie and authenticate as that administrator.

Affected Products

  • Grav CMS versions 2.0.19 through 2.0.24 (default-vulnerable configuration)
  • Grav CMS versions 2.0.0 through 2.0.18 (where content Twig has been explicitly enabled)
  • Grav CMS 1.7.x (where content Twig has been explicitly enabled; outside backport scope)

Discovery Timeline

  • 2026-09-26 - CVE-2026-100671 published to the National Vulnerability Database (NVD)
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100671

Vulnerability Analysis

The vulnerability combines a permissive Twig sandbox allowlist with a session-insensitive output cache. Grav's Twig sandbox exposes the get_cookie() function to page content authored by any user holding page-write permission. When a page containing this function is rendered, Twig executes server-side and reads cookies sent with the current HTTP request, including the viewer's session identifier.

Since version 2.0.19, the configuration flag security.twig_content.process_enabled defaults to true. The Security::applyTwigContentDefault() method derives each page's process.twig flag from this gate, so content Twig executes on every page without any frontmatter opt-in or operator action. This default-on behavior removes the historical barrier that previously required explicit enablement.

Root Cause

Two design defects compound to produce the exposure. First, the sandbox allowlist includes get_cookie(), a function that returns arbitrary request cookies rather than page-scoped data. Second, Grav's page-content cache keys entries on page identity and configuration checksum only, with no session, user, or request dimension and no bypass for authenticated visitors. The cache therefore stores and reuses output that includes a specific user's cookie value.

Attack Vector

An attacker with page-write permission authors a page whose Twig content invokes get_cookie() to embed the viewer's session cookie into the rendered output. When an administrator browses the page, Grav renders their session identifier into the page body and writes the result to the shared page-content cache. Subsequent anonymous requests to the same page receive the cached HTML containing the administrator's cookie. The attacker extracts the cookie and replays it to gain administrator access. The flaw is network-reachable and requires low privileges with user interaction from the victim administrator.

Detection Methods for CVE-2026-100671

Indicators of Compromise

  • Grav page content containing Twig invocations of get_cookie(), {{ get_cookie('grav-site-...') }}, or similar session-related cookie reads.
  • Cached page output files under the Grav cache directory containing values that match active session identifier patterns.
  • Unexpected authenticated administrator actions originating from IP addresses that previously only issued anonymous page views.

Detection Strategies

  • Audit all pages authored by non-administrator users for Twig expressions referencing get_cookie, session, or filter_input.
  • Inspect the Grav page cache directory for rendered HTML containing cookie-like strings or session tokens.
  • Review access logs for the same session cookie value being presented from multiple distinct client IP addresses within a short time window.

Monitoring Recommendations

  • Alert on new or modified pages committed by accounts without administrator privilege, especially those containing Twig tags.
  • Monitor administrator login events followed by anomalous privileged API calls from unfamiliar user agents or geolocations.
  • Track changes to security.twig_content.process_enabled and per-page process.twig frontmatter flags.

How to Mitigate CVE-2026-100671

Immediate Actions Required

  • Upgrade Grav to version 2.0.25 or later, which removes the unsafe allowlist entry and the cache sharing behavior for sensitive output.
  • Invalidate all existing administrator sessions and force password rotation for privileged accounts after upgrade.
  • Purge the Grav page-content cache to remove any entries that may contain captured session identifiers.

Patch Information

The maintainers released a fix in Grav 2.0.25. The 1.7.x branch is outside the backport scope and remains vulnerable where content Twig has been explicitly enabled. Review the GitHub Security Advisory GHSA-pp89-h475-7gj6 and the VulnCheck Advisory on Grav for release details.

Workarounds

  • Set security.twig_content.process_enabled to false in the Grav security configuration to disable content Twig processing globally.
  • Revoke page-write permission from untrusted accounts until the upgrade is deployed.
  • Place a caching reverse proxy or application-layer filter in front of Grav to strip response bodies containing session cookie patterns.
bash
# Configuration example: disable content Twig processing in user/config/security.yaml
twig_content:
  process_enabled: false

# Then clear the Grav cache
bin/grav clear-cache --all

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.