Medium severity6.5NVD Advisory· Published Aug 19, 2026· Updated Sep 9, 2026
CVE-2026-61842
CVE-2026-61842
Description
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that object without passing through GravSecurityPolicy::checkMethodAllowed. A user with page-author permissions can render sandboxed content that exposes plugins.* configuration secrets, including SMTP credentials, API keys, and plugin database credentials. This issue is fixed in version 2.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | < 2.0.2 | 2.0.2 |
Affected products
2Patches
Vulnerability mechanics
References
5News mentions
1- Grav CMS: 14 Vulnerabilities Including Critical Privilege Escalation Disclosed TogetherVypr Intelligence · Aug 19, 2026