THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-957r-qf9p-67xw (medium) — Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

[GHSA] GHSA-957r-qf9p-67xw (medium) — Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

medgithub_advisoriesPublished 2026-08-06

GHSA-957r-qf9p-67xw Severity: medium CVE: None

Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

The `create()` Twig function (introduced in 5.9.0) allows instantiation of arbitrary PHP classes from template code, restricted only by a 5-entry blocklist. `SplFileObject` is not in the blocklist, enabling arbitrary file read, including `.env` (security key, DB cred

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-957r-qf9p-67xw