THREAT OPS › Threat News › [GHSA] GHSA-3jhr-mxmx-38cx (high) — Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
[GHSA] GHSA-3jhr-mxmx-38cx (high) — Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
GHSA-3jhr-mxmx-38cx Severity: high CVE: CVE-2026-76839
Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
## Summary
`system/config/security.yaml`'s Twig sandbox policy allow-lists `offsetget` and `offsetexists` for `Grav\Common\User\Interfaces\UserInterface`. The concrete `Grav\Common\User\Dat
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-76839cve
- pwned@evil.comemail
Original source: https://github.com/advisories/GHSA-3jhr-mxmx-38cx