THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3jhr-mxmx-38cx (high) — Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

[GHSA] GHSA-3jhr-mxmx-38cx (high) — Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

medgithub_advisoriesPublished 2026-09-17

GHSA-3jhr-mxmx-38cx Severity: high CVE: CVE-2026-76839

Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

## Summary

`system/config/security.yaml`'s Twig sandbox policy allow-lists `offsetget` and `offsetexists` for `Grav\Common\User\Interfaces\UserInterface`. The concrete `Grav\Common\User\Dat

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3jhr-mxmx-38cx