PT-2025-48554 · Grav · Grav

Published

2025-12-01

·

Updated

2025-12-02

·

CVE-2025-66294

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.8.0-beta.27
Description Grav is a file-based Web platform susceptible to a Server-Side Template Injection (SSTI) issue. Authenticated attackers possessing editor permissions can execute arbitrary commands on the server. Under specific circumstances, unauthenticated attackers may also be able to exploit this issue. The root cause is weak regex validation within the cleanDangerousTwig method. This can potentially lead to remote code execution.
Recommendations Update to Grav version 1.8.0-beta.27 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-66294
GHSA-662M-56V4-3R8F

Affected Products

Grav