Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j274-39qw-32c9 | Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray() |
Thu, 14 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta1:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:beta4:*:*:*:*:*:* cpe:2.3:a:getgrav:grav:2.0.0:rc1:*:*:*:*:*:* |
Mon, 11 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgrav
Getgrav grav |
|
| Vendors & Products |
Getgrav
Getgrav grav |
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all plugin secrets (SMTP passwords, AWS keys, OAuth client secrets, API tokens) — into the rendered HTML. No administrator privileges are required. This vulnerability is fixed in 2.0.0-rc.2. | |
| Title | Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray() | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T18:06:17.679Z
Reserved: 2026-05-07T18:04:17.310Z
Link: CVE-2026-44738
Updated: 2026-05-14T18:03:19.535Z
Status : Modified
Published: 2026-05-11T17:16:34.747
Modified: 2026-05-14T18:16:50.440
Link: CVE-2026-44738
No data.
OpenCVE Enrichment
Updated: 2026-05-13T21:15:04Z
Github GHSA