CVE-2026-85604: Grav before 2.0.19 Remote Code Execution via sort filter

Published Sep 4, 2026
·
Updated

Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining denylist misses splautoload, which performs a PHP include. An authenticated user with only page-write rights (admin.pages or api.pages.write) can supply a crafted payload (e.g., via form frontmatter rendered by the Email plugin) that invokes splautoload through the sort filter, resulting in arbitrary PHP execution as the web server user.

Affected Software

1 affected component
Grav Grav<=2.0.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Grav CMS to a version that resolves this vulnerability.

    Fixed in 2.0.19
  2. Compensating control

    Restrict access so that only fully trusted administrators can create or edit content/frontmatter that is rendered with the Email plugin (limit authenticated page-write roles such as admin.pages or api.pages.write that could supply crafted payloads triggering the Twig sort filter).

Event History

Sep 4, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user with page-write rights can exploit it. The affected privileges are admin.pages or api.pages.write; no administrator-level access is required.

2

What access and conditions are required for exploitation?

The attacker needs authenticated page-write access and a way to supply crafted content that is rendered through the vulnerable Twig sort filter. The described example is form frontmatter rendered by the Email plugin.

3

What is the impact of successful exploitation?

Successful exploitation allows arbitrary PHP code execution as the web server user. This can affect confidentiality, integrity, and availability of the affected Grav deployment.

4

How can I determine whether an installation is affected?

Installations running Grav versions before 2.0.19 are affected; the provided affected-version range is versions 2.0.17 and earlier. Review whether users or API clients have admin.pages or api.pages.write permissions and whether they can submit content that is rendered by Twig.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203