File-Based Web Platform Vulnerability in Grav by GetGrav
CVE-2026-61842
6.5MEDIUM
What is CVE-2026-61842?
The file-based web platform Grav has a vulnerability where the Twig content sandbox allows users with page-author permissions to improperly access and display raw configuration objects. This can lead to leaks of sensitive information such as SMTP credentials, API keys, and database credentials, potentially compromising the security of the entire application. The issue has been addressed in version 2.0.2 to prevent unauthorized access to this critical data.
Affected Version(s)
grav < 2.0.2
