PT-2026-39647 · Grav · Grav

Revanth011

·

Published

2026-05-11

·

Updated

2026-05-14

·

CVE-2026-44738

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.0-rc.2
Description The Twig sandbox allow-list permits any user with the admin.pages role to call the config.toArray() function from within a page body. This action dumps the entire merged site configuration into the rendered HTML, potentially exposing sensitive plugin secrets such as SMTP passwords, AWS keys, OAuth client secrets, and API tokens. This process does not require administrator privileges.
Recommendations Update to version 2.0.0-rc.2.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-44738
GHSA-J274-39QW-32C9

Affected Products

Grav