Configuration Disclosure in Grav Flat-file CMS Affects Multiple Versions
CVE-2026-92917
8.7HIGH
What is CVE-2026-92917?
Grav Flat-file CMS versions 2.0.0-rc.1 through 2.0.21 are susceptible to a configuration disclosure vulnerability due to a failure in the Twig content sandbox. The flawed implementation of sandboxing allows authenticated users to exploit the {{ config|print_r }} functionality to gain direct access to sensitive configuration data. This includes the exposure of critical information such as SMTP credentials, API tokens, and other confidential secrets, potentially jeopardizing the security integrity of affected installations. The vulnerability is resolved in version 2.0.22 with the enhancement of filter restrictions.
Affected Version(s)
grav 2.0.0-rc.1 < 2.0.22
grav 2.0.22
