CVE-2026-55792: Craft CMS: Sensitive File Disclosure / Server-Side File Read
Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, the dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel user granted the utility:system-messages permission to embed a file-reading payload into system email templates. When those emails are sent, the server reads the target file and returns its contents as a base64-encoded data URL embedded in the email body. The .env file, which typically contains the database password, CRAFTSECURITYKEY, and third-party API keys, passes all of Craft’s existing dataUrl() protection checks and is fully exfiltrated. Obtaining CRAFTSECURITYKEY enables an attacker to forge session tokens and escalate to full admin account takeover. This issue has been fixed in versions 4.18.0 and 5.10.0.
Other sources
The dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel user granted the utility:system-messages permission to embed a file-reading payload into system email templates. When those emails are sent, the server reads the target file and returns its contents as a base64-encoded data URL embedded in the email body. The .env file, which typically contains the database password, CRAFTSECURITYKEY, and third-party API keys, passes all of Craft’s existing dataUrl() protection checks and is fully exfiltrated. Obtaining CRAFTSECURITYKEY enables an attacker to forge session tokens and escalate to full admin account takeover.
Details Affected versions: Craft CMS 4.x, 5.x (confirmed against 5.9.19)
The vulnerability arises from the combination of three code facts: 1. dataUrl is in the Twig sandbox allowlist src/config/twig-sandbox.php, line 115: php'allowedFunctions' => [ ... 'dataUrl', // ← allows file reading inside sandboxed templates ... ],
2. Html::dataUrl() does not block dotfiles src/helpers/Html.php, lines 1065–1090. The function applies four checks before reading a file:
Must be within the project root .env is at the root Must not be in a system directory (config/, vendor/, storage/, templates/) .env is not Must not be a .php file .env has no extension File must exist .env always exists in a Craft install
There is no check for dotfiles or specifically for .env. All four checks pass silently and filegetcontents() is called, with the result returned as data:text/plain;base64,....
3. System message body is rendered via renderSandboxedString() src/mail/Mailer.php, lines 181–183: php$subject = $view->renderSandboxedString($systemMessage->subject, $variables); $textBody = $view->renderSandboxedString($systemMessage->body, $variables); $htmlBody = $view->renderSandboxedString($systemMessage->body, $variables, escapeHtml: true);
Any body content saved to a system message is executed inside the Twig sandbox when the email renders. Because dataUrl is in allowedFunctions, the sandbox policy permits its execution without restriction.
Access control: The utility:system-messages permission is a non-admin CP permission grantable to any user group via Settings > Users > Groups. It is not restricted to admins.
Impact Vulnerability type: Sensitive File Disclosure / Server-Side File Read Who is impacted: Any Craft CMS 4.x or 5.x installation where at least one non-admin control panel user has been granted the utility:system-messages permission, and email sending is configured.
Resources:
- https://github.com/craftcms/cms/pull/18559
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 5.10.0 - Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 4.18.0 - Upgrade
Upgrade
Craft CMSto a version that resolves this vulnerability.Fixed in 4.18.0 - Upgrade
Upgrade
Craft CMSto a version that resolves this vulnerability.Fixed in 5.10.0 - Compensating control
Restrict the non-admin CP permission 'utility:system-messages' (Settings > Users > Groups) so that only trusted groups can send/edit system messages, since any user with this permission can embed a file-reading payload in system email templates via the Twig sandbox dataUrl() function.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55792?
The severity of CVE-2026-55792 is rated medium with a CVSS score of 6.
How do I fix CVE-2026-55792?
To mitigate CVE-2026-55792, upgrade Craft CMS to version 4.18.0 or 5.10.0 and above.
What is the risk associated with CVE-2026-55792?
CVE-2026-55792 poses a risk of sensitive file disclosure and server-side file read through the dataUrl() Twig function.
Which versions of Craft CMS are affected by CVE-2026-55792?
Craft CMS versions starting from 4.0.0-RC1 up to 4.18.0 and 5.0.0-RC1 up to 5.10.0 are affected by CVE-2026-55792.
What type of vulnerability is CVE-2026-55792 categorized as?
CVE-2026-55792 is categorized as an information leakage vulnerability.