THREAT OPS › Threat News › [GHSA] GHSA-957r-qf9p-67xw (medium) — Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
[GHSA] GHSA-957r-qf9p-67xw (medium) — Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
GHSA-957r-qf9p-67xw Severity: medium CVE: None
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
The `create()` Twig function (introduced in 5.9.0) allows instantiation of arbitrary PHP classes from template code, restricted only by a 5-entry blocklist. `SplFileObject` is not in the blocklist, enabling arbitrary file read, including `.env` (security key, DB cred
MITRE ATT&CK techniques
Original source: https://github.com/advisories/GHSA-957r-qf9p-67xw