Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-100671: Grav 2.0.19‑2.0.24 can leak admin session cookie

CVE-2026-100671 · published 2 days ago
Summary

Pages edited by a low‑privilege user can capture the browser cookie that identifies an administrator’s login. The cookie is saved in the site’s cache and later shown to anyone who views the page, allowing them to log in as the administrator. Update Grav to version 2.0.25 or later to stop this behavior.

What to do
  • Update getgrav grav to version 2.0.25 or later.
Affected software
VendorProductAffected versions
getgrav grav < 2.0.25
Original advisory text
Grav before 2.0.25 Session Cookie Theft via Twig Sandbox
Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a Twig sandbox that allowlists get_cookie(), which returns any cookie sent with the current request, including the visitor's session cookie. Because the read occurs server-side via filter_input(INPUT_COOKIE, ...), the HttpOnly, Secure and SameSite attributes offer no protection. Grav then stores the finished post-Twig output in a page-content cache keyed only on page identity and the configuration checksum, with no session, user or request dimension and no bypass for authenticated visitors. A page published by a page-write user can therefore capture the session identifier of the next administrator who views it, after which the cached output serves that identifier to unauthenticated visitors, who can replay the cookie to authenticate as that administrator. Since 2.0.19, security.twig_content.process_enabled defaults to true and Security::applyTwigContentDefault() derives each page's process.twig flag from that gate, so content Twig runs on every page with no frontmatter or operator action. Fixed in 2.0.25; 1.7.x is outside the backport scope.
Severity
8.6 High
CVSS 3.1: 8.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-200Information Exposure
Timeline
Published26 Sep 2026
Updated28 Sep 2026
First seen26 Sep 2026
Sources
CVE-2026-100671 · MITRE
Track software like this
Free during beta