← Back

CVE-2025-66299

nvd nist
Published: Dec 1, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypassing the existing security sandbox. Since the security sandbox does not fully protect the Twig object, it is possible to interact with it (e.g., call methods, read/write attributes) through maliciously crafted Twig template directives injected into a web page. This allows an authenticated editor to add arbitrary functions to the Twig attribute system.twig.safe_filters, effectively bypassing the Grav CMS sandbox. This vulnerability is fixed in 1.8.0-beta.27.

Affected (27)

Products: Getgrav: Grav
1 product
Grav
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Getgrav
Before 1.8.0
Version 1.8.0 beta10
Version 1.8.0 beta11
Version 1.8.0 beta12
Version 1.8.0 beta13
Version 1.8.0 beta14
Version 1.8.0 beta15
Version 1.8.0 beta16
Version 1.8.0 beta17
Version 1.8.0 beta18
Version 1.8.0 beta19
Version 1.8.0 beta1
Version 1.8.0 beta20
Version 1.8.0 beta21
Version 1.8.0 beta22
Version 1.8.0 beta23
Version 1.8.0 beta24
Version 1.8.0 beta25
Version 1.8.0 beta26
Version 1.8.0 beta2
Version 1.8.0 beta3
Version 1.8.0 beta4
Version 1.8.0 beta5
Version 1.8.0 beta6
Version 1.8.0 beta7
Version 1.8.0 beta8
Version 1.8.0 beta9

References (2)

Source: security-advisories@github.com
ExploitThird Party Advisory

Timeline

No history available yet.