THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2c4f-86xc-cr74 (medium) — Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

[GHSA] GHSA-2c4f-86xc-cr74 (medium) — Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

highgithub_advisoriesPublished 2026-09-16

GHSA-2c4f-86xc-cr74 Severity: medium CVE: CVE-2026-61453

Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

## Summary

The XSS blueprint validator (`Security::detectXss()`) runs on the **raw page content before Twig processing**. An attacker can use Twig's string concatenation operator (`~`) to dynamically construct an event handler name at render time. The validator sees `{{ "

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2c4f-86xc-cr74