What is CVE-2026-61842?
CVE-2026-61842 is a critical vulnerability in the Grav file-based web platform. Prior to version 2.0.2, the Twig content sandbox allows leaking raw configuration objects via specific filters, bypassing security restrictions. Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-61842, Grav fayl-əsaslı veb platformasında aşkar edilmiş kritik boşluqdur. 2.0.2 versiyasından əvvəlki məhsullarda Twig şablon sandbox-u müəyyən filtrlər vasitəsilə konfiqurasiya məlumatlarının sızmasına imkan verir. Dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which platform does CVE-2026-61842 affect?
It affects the Grav file-based web platform.
What should I do to protect against CVE-2026-61842?
You should immediately update to version 2.0.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.