THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8hgv-xc77-jmcr (medium) — Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin

[GHSA] GHSA-8hgv-xc77-jmcr (medium) — Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin

medgithub_advisoriesPublished 2026-08-21

GHSA-8hgv-xc77-jmcr Severity: medium CVE: None

Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin

## Summary

Grav 2.0 renders editor-authored Twig in page content by default and relies on the Twig content sandbox to contain it. The shipped sandbox policy allowlists `addcss` and `addjs` on `Grav\Commo

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-8hgv-xc77-jmcr