<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:05:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-196424</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-196424</link>
      <description>EUVD-2026-196424</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-196424</guid>
    </item>
    <item>
      <title>fkie_cve-2023-37897</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37897</link>
      <description>&lt;p&gt;Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash (`\\`). The `isDangerousFunction()` check in version 1.7.42 and onwards retuns `false` value instead of `true` when the `\` symbol is found in the `$name`. This vulnerability can be exploited if the attacker has access to: 1. an Administrator account, or 2. a non-administrator, user account that has Admin panel access and Create/Update page permissions. A fix for this vulnerability has been introduced in commit `b4c6210` and is included in release version `1.7.42.2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash (`\\`). The `isDangerousFunction()` check in version 1.7.42 and onwards retuns `false` value instead of `true` when the `\` symbol is found in the `$name`. This vulnerability can be exploited if the attacker has access to: 1. an Administrator account, or 2. a non-administrator, user account that has Admin panel access and Create/Update page permissions. A fix for this vulnerability has been introduced in commit `b4c6210` and is included in release version `1.7.42.2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-37897</guid>
    </item>
    <item>
      <title>GHSA-9436-3gmp-4f53 — grav Server-side Template Injection (SSTI) mitigation bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9436-3gmp-4f53</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;### Summary
The fix for SSTI using `|map`, `|filter` and `|reduce` twigs implemented in the commit [71bbed1](https://github.com/getgrav/grav/commit/71bbed12f950de8335006d7f91112263d8504f1b) introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash (`\\`)&lt;/p&gt;
&lt;p&gt;### Details
The `isDangerousFunction()` check in version 1.7.42 and onwards retuns `false` value instead of `true` when the `\` symbol is found in the `$name`.&lt;/p&gt;
&lt;p&gt;```php
...
        if (strpos($name, &amp;#34;\\&amp;#34;) !== false) {
            return false;
        }&lt;/p&gt;
&lt;p&gt;if (in_array($name, $commandExecutionFunctions)) {
            return true;
        }
...
```
Based on the code where the function is used, it is expected that any dangerous condition would return `true`
```php
    /**
     * @param Environment $env
     * @param array $array
     * @param callable|string $arrow
     * @return array|CallbackFilterIterator
     * @throws RuntimeError
     */
    function mapFunc(Environment $env, $array, $arrow)
    {
        if (!$arrow instanceof \Closure &amp;amp;&amp;amp; !is_string($arrow) || Utils::isDangerousFunction($arrow)) {
            throw new RuntimeError(&amp;#39;Twig |map(&amp;#34;&amp;#39; . $arrow . &amp;#39;&amp;#34;) is not allowed.&amp;#39;);
	}
```
when `|map(&amp;#39;\system&amp;#39;)` is used in the malicious payload, the single backslash is dropped prior to reaching `strpos($name, &amp;#39;\\&amp;#39;)` check, thus `$name` variable already has no backslash, and the command is blacklisted because it reache…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;### Summary
The fix for SSTI using `|map`, `|filter` and `|reduce` twigs implemented in the commit [71bbed1](https://github.com/getgrav/grav/commit/71bbed12f950de8335006d7f91112263d8504f1b) introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash (`\\`)&lt;/p&gt;
&lt;p&gt;### Details
The `isDangerousFunction()` check in version 1.7.42 and onwards retuns `false` value instead of `true` when the `\` symbol is found in the `$name`.&lt;/p&gt;
&lt;p&gt;```php
...
        if (strpos($name, &amp;#34;\\&amp;#34;) !== false) {
            return false;
        }&lt;/p&gt;
&lt;p&gt;if (in_array($name, $commandExecutionFunctions)) {
            return true;
        }
...
```
Based on the code where the function is used, it is expected that any dangerous condition would return `true`
```php
    /**
     * @param Environment $env
     * @param array $array
     * @param callable|string $arrow
     * @return array|CallbackFilterIterator
     * @throws RuntimeError
     */
    function mapFunc(Environment $env, $array, $arrow)
    {
        if (!$arrow instanceof \Closure &amp;amp;&amp;amp; !is_string($arrow) || Utils::isDangerousFunction($arrow)) {
            throw new RuntimeError(&amp;#39;Twig |map(&amp;#34;&amp;#39; . $arrow . &amp;#39;&amp;#34;) is not allowed.&amp;#39;);
	}
```
when `|map(&amp;#39;\system&amp;#39;)` is used in the malicious payload, the single backslash is dropped prior to reaching `strpos($name, &amp;#39;\\&amp;#39;)` check, thus `$name` variable already has no backslash, and the command is blacklisted because it reache…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9436-3gmp-4f53</guid>
    </item>
    <item>
      <title>gsd-2023-37897</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-37897</link>
      <description>gsd-2023-37897</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-37897</guid>
    </item>
  </channel>
</rss>
