THREAT OPS › Threat News › [GHSA] GHSA-p597-crqc-m349 (high) — Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
[GHSA] GHSA-p597-crqc-m349 (high) — Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
GHSA-p597-crqc-m349 Severity: high CVE: CVE-2026-72698
Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
## Summary
`Grav\Common\Twig\Twig::init()` unconditionally puts the raw `system`, `site`, and `theme` config arrays into `$this->twig_vars`. `Twig::processPage()` builds the variables for the sandboxed, editor-au
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- c2b46866857a93a0aa7048e7ed707ed3ed45dbc3sha1
- 24d7a0e821cf573496d99e05d6bd9d1a42f822c7sha1
- CVE-2026-72698cve
- packagist.orgdomain
Original source: https://github.com/advisories/GHSA-p597-crqc-m349