THREAT OPS › Threat News › [GHSA] GHSA-596p-6jv8-775v (medium) — Craft CMS: Authenticated leak of secret environment variables
[GHSA] GHSA-596p-6jv8-775v (medium) — Craft CMS: Authenticated leak of secret environment variables
GHSA-596p-6jv8-775v Severity: medium CVE: None
Craft CMS: Authenticated leak of secret environment variables
Environment variables and secrets are interpolated into a Twig template even when the Twig sandbox is enabled, allowing them to be leaked by an authenticated attacker.
The Craft vulnerability CVE-2026-31857 was on
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-31857cve
Original source: https://github.com/advisories/GHSA-596p-6jv8-775v