THREAT OPS › Threat News › [NVD] CVE-2026-85604 (HIGH 8.8) — Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name i
[NVD] CVE-2026-85604 (HIGH 8.8) — Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name i
CVE-2026-85604 CVSS: 8.8 HIGH Published: 2026-09-04T12:17:24.177
Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining denylist misses spl_a
Indicators of compromise
- CVE-2026-85604cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85604