<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:56:12.614472+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-358812</id>
    <title>EUVD-2026-358812</title>
    <updated>2026-10-06T18:56:12.665890+00:00</updated>
    <content>EUVD-2026-358812</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-358812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-76839</id>
    <title>fkie_cve-2026-76839</title>
    <updated>2026-10-06T18:56:12.665927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-76839"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3jhr-mxmx-38cx</id>
    <title>GHSA-3jhr-mxmx-38cx — Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_passwor…</title>
    <updated>2026-10-06T18:56:12.665958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getgrav/grav</p>
<p>## Summary</p>
<p>`system/config/security.yaml`'s Twig sandbox policy allow-lists `offsetget` and
`offsetexists` for `Grav\Common\User\Interfaces\UserInterface`. The concrete
`Grav\Common\User\DataUser\User` class does not filter which fields `offsetGet()`
returns, so any sandboxed template with access to a `User` object can read
`hashed_password`, `secret` (2FA seed), and `twofa_secret` directly, bypassing the
redaction Grav's own code applies everywhere else.</p>
<p>## The core evidence, from Grav's own code</p>
<p>`system/src/Grav/Common/User/DataUser/User.php`:</p>
<p>```php
/**
 * {@inheritdoc}
 * Override to filter out sensitive fields like password hashes
 */
public function jsonSerialize(): array
{
    $items = parent::jsonSerialize();</p>
<p>// Security: Remove sensitive fields that should never be exposed to frontend
    unset($items['hashed_password']);
    unset($items['secret']);         // 2FA secret
    unset($items['twofa_secret']);   // Alternative 2FA field name</p>
<p>return $items;
}</p>
<p>public function offsetGet($offset)
{
    $value = parent::offsetGet($offset);
    // only special-cases 'authorized', nothing else -- no redaction
    return $value;
}
```</p>
<p>`system/config/security.yaml`:</p>
<p>```yaml
- class: 'Grav\Common\User\Interfaces\UserInterface'
  methods: 'authorize, authorized, authenticated, username, fullname, email, language, offsetget, offsetexists'
```</p>
<p>This is the same vulnerability shape as two already-fixed issues in this file
(GHSA-j274-39qw-32c9 and GHSA-mc5q-6hpj-rp7j -…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3jhr-mxmx-38cx"/>
  </entry>
</feed>
