Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-cxgw-r5jg-7xwq: Code injection in grav

Grav is vulnerable to Server Side Template Injection via Twig. According to a previous vulnerability report, Twig should not render dangerous functions by default, such as system.

ghsa
#vulnerability#git

Code injection in grav

Critical severity GitHub Reviewed Published Jun 30, 2022 • Updated Jul 5, 2022

Related news

CVE-2022-2073: Fixed Twig `|filter()` allowing code execution · getgrav/grav@9d6a2db

Code Injection in GitHub repository getgrav/grav prior to 1.7.34.