PKSA-rk3g-1sfp-78gs Security Advisory
-
[HIGH] Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
PKSA-rk3g-1sfp-78gs CVE-2026-76846 GHSA-xjw5-q542-3vmr
Affected package: getgrav/grav
Affected version: <=2.0.15
Reported by:
GitHub