Логотип exploitDog
bind: "CVE-2025-66294"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-66294"

Количество 2

Количество 2

nvd логотип

CVE-2025-66294

17 дней назад

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, under certain conditions, may also be exploited by unauthenticated attackers. This vulnerability stems from weak regex validation in the cleanDangerousTwig method. This vulnerability is fixed in 1.8.0-beta.27.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-662m-56v4-3r8f

17 дней назад

Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66294

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, under certain conditions, may also be exploited by unauthenticated attackers. This vulnerability stems from weak regex validation in the cleanDangerousTwig method. This vulnerability is fixed in 1.8.0-beta.27.

CVSS3: 8.8
47%
Средний
17 дней назад
github логотип
GHSA-662m-56v4-3r8f

Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass

47%
Средний
17 дней назад

Уязвимостей на страницу