<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T01:00:25.514694+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356475</id>
    <title>EUVD-2026-356475</title>
    <updated>2026-10-10T01:00:25.517138+00:00</updated>
    <content>EUVD-2026-356475</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61842</id>
    <title>fkie_cve-2026-61842</title>
    <updated>2026-10-10T01:00:25.517179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that object without passing through GravSecurityPolicy::checkMethodAllowed. A user with page-author permissions can render sandboxed content that exposes plugins.* configuration secrets, including SMTP credentials, API keys, and plugin database credentials. This issue is fixed in version 2.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61842"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mc5q-6hpj-rp7j</id>
    <title>GHSA-mc5q-6hpj-rp7j — Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)</title>
    <updated>2026-10-10T01:00:25.517224+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getgrav/grav</p>
<p>### Summary</p>
<p>The Twig content sandbox replaces `config` with the redacted `SandboxConfig` facade and strips `Config::get`/`toArray` from the method allowlist (GHSA-j274-39qw-32c9), so editor content can't read config secrets via `config`. That's bypassable: `grav` is the raw container, `offsetget` is allow-listed on it, so `grav.offsetGet('config')` returns the real `Config`. The allow-listed filters `json_encode`/`print_r`/`yaml_encode` then serialize it at the PHP level, never hitting the sandbox method gate, dumping the whole config tree including every `plugins.*` secret (SMTP creds, API keys, plugin DB creds). Incomplete fix for GHSA-j274-39qw-32c9. `security.salt` does not leak (it lives outside config).</p>
<p>### Details</p>
<p>The documented path is blocked: `config` is the `SandboxConfig` facade (`Twig.php:660`) and the raw `Config`/`Data` method entries are stripped when `config_access` is false, so `{{ config.get(...) }}` returns the default and `{{ grav.offsetGet('config').get(...) }}` raises `SecurityNotAllowedMethodError`.</p>
<p>The bypass uses two allow-listed primitives the redaction doesn't cover:</p>
<p>1. `grav.offsetGet('config')` returns the raw `Config`. The `SandboxConfig` facade replaces only the `config` variable, not `grav['config']`; `offsetget` is allow-listed on `Grav\Common\Grav` in `system/config/security.yaml`.
2. `json_encode`/`print_r`/`yaml_encode` serialize the object inside the filter and never call `GravSecurityPolicy::checkMethodAllowed` (`GravSecurityPolicy…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mc5q-6hpj-rp7j"/>
  </entry>
</feed>
