PT-2025-51250 · Grav · Grav

Yohane-Mashiro

·

Published

2025-12-15

·

Updated

2025-12-15

·

CVE-2025-66844

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions grav versions prior to 1.7.49.5
Description A Server-Side Request Forgery (SSRF) issue exists in grav. The issue occurs when page content is processed by Twig templates, and the configuration allows undefined PHP functions to be registered. This can be triggered via Twig templates. SSRF allows an attacker to cause the server to make requests to unintended locations.
Recommendations Update grav to version 1.7.49.5 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-66844
GHSA-729W-J79F-2C34

Affected Products

Grav