{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/grav-1.7.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8,"id":"CVE-2026-100671"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav (1.7.x)","Grav (2.0.0 through 2.0.24)","Grav (\u003c 2.0.25)"],"_cs_severities":["high"],"_cs_tags":["web-application","security-misconfiguration","cve-2026-100669"],"_cs_type":"threat","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eGrav CMS versions 1.7.x and 2.0.0 through 2.0.24 contain a vulnerability in the Twig sandbox configuration. Specifically, the get_cookie() function is allowlisted for use within page content. A user with page-write permissions can inject Twig template code to read arbitrary browser cookies from any user who visits the crafted page. This attack bypasses standard security protections such as the HttpOnly, Secure, and SameSite attributes because the extraction occurs server-side.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is compounded by the Grav page-content caching mechanism, which stores the processed output of Twig-enabled pages without scoping the cache to the viewing user's session or identity. When an administrator views the crafted page, their session cookie is captured and embedded into the cached version of the content. Subsequent unauthenticated visitors to that page receive the cached content containing the administrator's session identifier. This allows unauthorized attackers to replay the stolen session cookie to hijack administrative access. In version 2.0.19 and later, Twig content processing is enabled by default, increasing the exploit surface. The issue was addressed in version 2.0.25.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains or registers a user account with page-write privileges on the target Grav CMS.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the administrative interface to create or edit a page.\u003c/li\u003e\n\u003cli\u003eThe attacker injects malicious Twig code containing \u003ccode\u003e{{ get_cookie('session_cookie_name') }}\u003c/code\u003e into the page content.\u003c/li\u003e\n\u003cli\u003eThe attacker saves the page, triggering the server to render the Twig code during the next page load.\u003c/li\u003e\n\u003cli\u003eAn administrator visits the crafted page, causing the server to execute the injected code and extract the administrator's session cookie.\u003c/li\u003e\n\u003cli\u003eThe server stores the resulting rendered output in the system's global page cache, including the captured sensitive cookie data.\u003c/li\u003e\n\u003cli\u003eThe attacker or another unauthenticated user requests the crafted page and receives the cached content containing the administrator's session token.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the intercepted session token to impersonate the administrator and gain unauthorized administrative control.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete administrative account takeover of the Grav CMS instance. This can lead to unauthorized modification of site content, configuration changes, and potential remote code execution depending on the privileges and plugins associated with the hijacked administrative session. The scope includes all Grav deployments running vulnerable versions where Twig content rendering is enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Grav CMS to version 2.0.25 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit all pages authored by users with page-write permissions for the presence of Twig syntax or suspicious template code.\u003c/li\u003e\n\u003cli\u003eDisable Twig content processing if it is not required for site functionality by setting \u003ccode\u003esecurity.twig_content.process_enabled\u003c/code\u003e to \u003ccode\u003efalse\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eReview administrative access logs for unusual session activity or successful logins originating from disparate IP addresses following the period of exposure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T17:00:21Z","date_published":"2026-09-26T15:09:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-grav-cms-twig-sandbox/","summary":"Grav CMS versions 1.7.x and 2.0.0 through 2.0.24 are vulnerable to session hijacking due to an improperly restricted get_cookie() function within the Twig rendering engine.","title":"Grav CMS Session Hijacking via Twig Sandbox Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-grav-cms-twig-sandbox/"}],"language":"en","title":"CraftedSignal Threat Feed - Grav (1.7.x)","version":"https://jsonfeed.org/version/1.1"}