Junglewise Threat Intelligence

CVE-2026-75574: Grav Email plugin unsandboxed Twig template injection

CVE-2026-75574 · Severity: high · CVSS 8.8 · Published 2026-08-25

Vendors: Grav.

Executive brief

Grav is a flat-file CMS platform used to build websites. The Email plugin fails to restrict Twig template execution when processing email parameters provided by page editors, allowing an authenticated user with basic write permissions to inject arbitrary code and execute system commands as the PHP process user.

Technical details

The vulnerability is a template injection flaw in the Email plugin's parameter processing. A page editor can inject Twig expressions into the header.form.process.email.body field via the API (requires only api.access and api.pages.write permissions), which are then rendered outside the Twig sandbox without proper filtering. When the form is submitted, the Email plugin processes these parameters through processTwigString() using an @EmailVar: template source that bypasses sandbox restrictions. An attacker can call grav.scheduler.addCommand() through unsandboxed Twig to execute arbitrary OS commands as the PHP account. No admin privileges, existing credentials, or working mail server are required; only authenticated API access is needed.

Affected products

  • Grav Email plugin before 4.2.2

Timeline

  • 2026-08-10: disclosed
  • 2026-08-25: advisory: NVD published CVE-2026-75574
  • 2026-08-25: patched: Version 4.2.2 patches the vulnerability

References