SSRF Vulnerability in Grav by Get Grav
CVE-2025-66844

9.1CRITICAL

Key Information:

Vendor

Get Grav

Status
Vendor
CVE Published:
15 December 2025

What is CVE-2025-66844?

A vulnerability exists in Grav versions earlier than 1.7.49.5 that may be exploited through a Server-Side Request Forgery (SSRF) vector. This issue arises when page content is processed through Twig templates, allowing an attacker to trigger unauthorized requests if the configuration permits the registration of undefined PHP functions. This can potentially expose the server to further attacks or sensitive data leakage.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.