THREAT OPS › Threat News › [GHSA] GHSA-xv9m-fm3w-8w5x (low) — October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
[GHSA] GHSA-xv9m-fm3w-8w5x (low) — October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
GHSA-xv9m-fm3w-8w5x Severity: low CVE: CVE-2026-46696
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
A vulnerability was identified in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and raw SQL methods reachable through Eloquent's `_
Indicators of compromise
- CVE-2026-46696cve
Original source: https://github.com/advisories/GHSA-xv9m-fm3w-8w5x