CVE-2025-66844

CRITICAL9.1EPSS 0.06%

Grav may be vulnerable to SSRF attack via Twig Templates

Published: 12/15/2025Modified: 12/17/2025
Also known as:GHSA-729w-j79f-2c34

Description

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References (3)