PT-2025-48554 · Grav · Grav
Published
2025-12-01
·
Updated
2025-12-02
·
CVE-2025-66294
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 1.8.0-beta.27
Description
Grav is a file-based Web platform susceptible to a Server-Side Template Injection (SSTI) issue. Authenticated attackers possessing editor permissions can execute arbitrary commands on the server. Under specific circumstances, unauthenticated attackers may also be able to exploit this issue. The root cause is weak regex validation within the
cleanDangerousTwig method. This can potentially lead to remote code execution.Recommendations
Update to Grav version 1.8.0-beta.27 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grav