THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-85604 (HIGH 8.8) — Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name i

[NVD] CVE-2026-85604 (HIGH 8.8) — Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name i

mednvdPublished 2026-09-04

CVE-2026-85604 CVSS: 8.8 HIGH Published: 2026-09-04T12:17:24.177

Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining denylist misses spl_a

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85604