THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-47ch-6w46-6xm7 (high) — Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

[GHSA] GHSA-47ch-6w46-6xm7 (high) — Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

highgithub_advisoriesPublished 2026-09-17

GHSA-47ch-6w46-6xm7 Severity: high CVE: CVE-2026-72697

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

## Summary

The `media_directory()` Twig function is allow-listed for use in sandboxed, editor-authored page content (`system/config/security.yaml`). Its implementation, `GravExtension::mediaDirFunc()`, only treats t

Indicators of compromise

Original source: https://github.com/advisories/GHSA-47ch-6w46-6xm7