PKSA-wz98-fgrh-3wq2 Security Advisory
-
[HIGH] Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
PKSA-wz98-fgrh-3wq2 CVE-2026-72698 GHSA-p597-crqc-m349
Affected package: getgrav/grav
Affected version: <2.0.16
Reported by:
GitHub