Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5fvc-7894-ghp4 | Craft CMS has Twig Function Blocklist Bypass |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 04 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack, you need to either have allowAdminChanges enabled on production, or a compromised admin account, or an account with access to the System Messages utility. Several PHP functions are not included in the blocklist, which could allow malicious actors with the required permissions to execute various types of payloads, including RCEs, arbitrary file reads, SSRFs, and SSTIs. This vulnerability is fixed in 5.9.0-beta.1 and 4.17.0-beta.1. | |
| Title | Craft has a Twig Function Blocklist Bypass | |
| Weaknesses | CWE-1336 CWE-184 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-04T17:34:05.130Z
Reserved: 2026-03-03T14:25:19.244Z
Link: CVE-2026-28783
Updated: 2026-03-04T17:34:00.593Z
Status : Awaiting Analysis
Published: 2026-03-04T17:16:21.690
Modified: 2026-03-04T18:08:05.730
Link: CVE-2026-28783
No data.
OpenCVE Enrichment
No data.
Github GHSA