Grav CMS Twig sandbox bypass: XSS via assets.addJs enables privilege escalation
Security Advisory
GHSA-8hgx-xc77-jmcr
High
Grav
Affected:
- Grav <= 2.0.19
Fixed in:
- 2.0.20
Referenced CVEs:
CVE-2026-86197 · 5.1
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.