THREAT OPS › Threat News › [GHSA] GHSA-xjw5-q542-3vmr (high) — Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
[GHSA] GHSA-xjw5-q542-3vmr (high) — Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
GHSA-xjw5-q542-3vmr Severity: high CVE: CVE-2026-76846
Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
## Summary
`system/config/security.yaml`'s default `twig_sandbox.config_denied_paths` list (`plugins`, `streams`, `security`, `backups`, `scheduler`) omits the `system` prefix. Wh
Indicators of compromise
- CVE-2026-76846cve
Original source: https://github.com/advisories/GHSA-xjw5-q542-3vmr