THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xjw5-q542-3vmr (high) — Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

[GHSA] GHSA-xjw5-q542-3vmr (high) — Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

medgithub_advisoriesPublished 2026-09-17

GHSA-xjw5-q542-3vmr Severity: high CVE: CVE-2026-76846

Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

## Summary

`system/config/security.yaml`'s default `twig_sandbox.config_denied_paths` list (`plugins`, `streams`, `security`, `backups`, `scheduler`) omits the `system` prefix. Wh

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xjw5-q542-3vmr