Configuration Disclosure in Grav Flat-file CMS Affects Multiple Versions
CVE-2026-92917

8.7HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92917?

Grav Flat-file CMS versions 2.0.0-rc.1 through 2.0.21 are susceptible to a configuration disclosure vulnerability due to a failure in the Twig content sandbox. The flawed implementation of sandboxing allows authenticated users to exploit the {{ config|print_r }} functionality to gain direct access to sensitive configuration data. This includes the exposure of critical information such as SMTP credentials, API tokens, and other confidential secrets, potentially jeopardizing the security integrity of affected installations. The vulnerability is resolved in version 2.0.22 with the enhancement of filter restrictions.

Affected Version(s)

grav 2.0.0-rc.1 < 2.0.22

grav 2.0.22

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vectrain51
.