<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:15:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-358812</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358812</link>
      <description>EUVD-2026-358812</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358812</guid>
    </item>
    <item>
      <title>fkie_cve-2026-76839</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-76839</link>
      <description>&lt;p&gt;Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-76839</guid>
    </item>
    <item>
      <title>GHSA-3jhr-mxmx-38cx — Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_passwor…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3jhr-mxmx-38cx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`system/config/security.yaml`&amp;#39;s Twig sandbox policy allow-lists `offsetget` and
`offsetexists` for `Grav\Common\User\Interfaces\UserInterface`. The concrete
`Grav\Common\User\DataUser\User` class does not filter which fields `offsetGet()`
returns, so any sandboxed template with access to a `User` object can read
`hashed_password`, `secret` (2FA seed), and `twofa_secret` directly, bypassing the
redaction Grav&amp;#39;s own code applies everywhere else.&lt;/p&gt;
&lt;p&gt;## The core evidence, from Grav&amp;#39;s own code&lt;/p&gt;
&lt;p&gt;`system/src/Grav/Common/User/DataUser/User.php`:&lt;/p&gt;
&lt;p&gt;```php
/**
 * {@inheritdoc}
 * Override to filter out sensitive fields like password hashes
 */
public function jsonSerialize(): array
{
    $items = parent::jsonSerialize();&lt;/p&gt;
&lt;p&gt;// Security: Remove sensitive fields that should never be exposed to frontend
    unset($items[&amp;#39;hashed_password&amp;#39;]);
    unset($items[&amp;#39;secret&amp;#39;]);         // 2FA secret
    unset($items[&amp;#39;twofa_secret&amp;#39;]);   // Alternative 2FA field name&lt;/p&gt;
&lt;p&gt;return $items;
}&lt;/p&gt;
&lt;p&gt;public function offsetGet($offset)
{
    $value = parent::offsetGet($offset);
    // only special-cases &amp;#39;authorized&amp;#39;, nothing else -- no redaction
    return $value;
}
```&lt;/p&gt;
&lt;p&gt;`system/config/security.yaml`:&lt;/p&gt;
&lt;p&gt;```yaml
- class: &amp;#39;Grav\Common\User\Interfaces\UserInterface&amp;#39;
  methods: &amp;#39;authorize, authorized, authenticated, username, fullname, email, language, offsetget, offsetexists&amp;#39;
```&lt;/p&gt;
&lt;p&gt;This is the same vulnerability shape as two already-fixed issues in this file
(GHSA-j274-39qw-32c9 and GHSA-mc5q-6hpj-rp7j -…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`system/config/security.yaml`&amp;#39;s Twig sandbox policy allow-lists `offsetget` and
`offsetexists` for `Grav\Common\User\Interfaces\UserInterface`. The concrete
`Grav\Common\User\DataUser\User` class does not filter which fields `offsetGet()`
returns, so any sandboxed template with access to a `User` object can read
`hashed_password`, `secret` (2FA seed), and `twofa_secret` directly, bypassing the
redaction Grav&amp;#39;s own code applies everywhere else.&lt;/p&gt;
&lt;p&gt;## The core evidence, from Grav&amp;#39;s own code&lt;/p&gt;
&lt;p&gt;`system/src/Grav/Common/User/DataUser/User.php`:&lt;/p&gt;
&lt;p&gt;```php
/**
 * {@inheritdoc}
 * Override to filter out sensitive fields like password hashes
 */
public function jsonSerialize(): array
{
    $items = parent::jsonSerialize();&lt;/p&gt;
&lt;p&gt;// Security: Remove sensitive fields that should never be exposed to frontend
    unset($items[&amp;#39;hashed_password&amp;#39;]);
    unset($items[&amp;#39;secret&amp;#39;]);         // 2FA secret
    unset($items[&amp;#39;twofa_secret&amp;#39;]);   // Alternative 2FA field name&lt;/p&gt;
&lt;p&gt;return $items;
}&lt;/p&gt;
&lt;p&gt;public function offsetGet($offset)
{
    $value = parent::offsetGet($offset);
    // only special-cases &amp;#39;authorized&amp;#39;, nothing else -- no redaction
    return $value;
}
```&lt;/p&gt;
&lt;p&gt;`system/config/security.yaml`:&lt;/p&gt;
&lt;p&gt;```yaml
- class: &amp;#39;Grav\Common\User\Interfaces\UserInterface&amp;#39;
  methods: &amp;#39;authorize, authorized, authenticated, username, fullname, email, language, offsetget, offsetexists&amp;#39;
```&lt;/p&gt;
&lt;p&gt;This is the same vulnerability shape as two already-fixed issues in this file
(GHSA-j274-39qw-32c9 and GHSA-mc5q-6hpj-rp7j -…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3jhr-mxmx-38cx</guid>
    </item>
  </channel>
</rss>
