CRITICAL🇵🇱 Wersja polska

CVE-2025-66844

CVSS 9.1v3.1pub. 2025-12-15upd. 2025-12-17

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered

🤖 AI Analysis
How it works

The vulnerability is triggered through Twig templates during page content processing when the application configuration allows registration of undefined PHP functions. An attacker can craft appropriate code in a Twig template that will cause the server to execute an HTTP request to internal or external network resources. No authentication or user interaction is required, meaning the exploit can be carried out remotely over the network.

Impact

An attacker can gain access to sensitive internal network infrastructure resources and manipulate network traffic generated by the server, which may lead to disclosure of sensitive data and system integrity violation.

Mitigation & patch

Grav should be updated to version 1.7.49.5 or later. Additionally, it is recommended to verify the application configuration to restrict the possibility of registering undefined PHP functions in Twig templates.

Who is affected

Getgrav Grav in versions below 1.7.49.5

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Getgrav Grav

    APP
    Getgrav
    < 1.7.49.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2021-47812CRITICAL9.3PL ✓same product

GravCMS – nieuwierzytelniony zapis YAML i zdalne wykonanie kodu PHP

CVE-2025-46199CRITICAL9.8PL ✓same product

XSS umożliwiający wykonanie kodu w Getgrav Grav (≤ 1.7.48)

CVE-2023-34251CRITICAL9.9PL ✓same product

Grav CMS: Server Side Template Injection umożliwia RCE

CVE-2026-42844HIGH8.7same product

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.medi...

CVE-2026-42608HIGH8.8same product

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the F...