THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p597-crqc-m349 (high) — Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

[GHSA] GHSA-p597-crqc-m349 (high) — Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

highgithub_advisoriesPublished 2026-09-17

GHSA-p597-crqc-m349 Severity: high CVE: CVE-2026-72698

Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

## Summary

`Grav\Common\Twig\Twig::init()` unconditionally puts the raw `system`, `site`, and `theme` config arrays into `$this->twig_vars`. `Twig::processPage()` builds the variables for the sandboxed, editor-au

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p597-crqc-m349