THREAT OPS › Threat News › [GHSA] GHSA-47ch-6w46-6xm7 (high) — Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
[GHSA] GHSA-47ch-6w46-6xm7 (high) — Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
GHSA-47ch-6w46-6xm7 Severity: high CVE: CVE-2026-72697
Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
## Summary
The `media_directory()` Twig function is allow-listed for use in sandboxed, editor-authored page content (`system/config/security.yaml`). Its implementation, `GravExtension::mediaDirFunc()`, only treats t
Indicators of compromise
- c2b46866857a93a0aa7048e7ed707ed3ed45dbc3sha1
- c569a53304cd7d95ff21bffa6fc590adcf0be83dsha1
- 8cfe7f74ac22a433d303914eba9ea4c2a834edcesha1
- c71ecc56dfe541dbd90c5360474fbc405f8d5963sha1
- CVE-2026-72697cve
Original source: https://github.com/advisories/GHSA-47ch-6w46-6xm7