CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-957R-QF9P-67XW

GHSA-957R-QF9P-67XW: Arbitrary File Read via SplFileObject in Craft CMS Twig Extension

Alon Barad
Alon Barad
Software Engineer

Aug 6, 2026·6 min read·12 visits

Executive Summary (TL;DR)

Craft CMS administrators with template capabilities can read sensitive server files (such as .env and system configurations) by abusing an omission in the dynamic class helper's blocklist to instantiate PHP's SplFileObject.

An information disclosure vulnerability in Craft CMS allows users with administrative or non-sandboxed template-authoring privileges to read arbitrary system and configuration files. The issue stems from an incomplete class instantiation blocklist in the Twig template extension, which omitted PHP's built-in SplFileObject class.

Vulnerability Overview

Craft CMS is a content management system built on PHP and the Twig template engine. To facilitate dynamic operations, the platform implements custom Twig extensions that expose utility helper functions directly inside template environments. One such helper is the create() function, designed to allow template authors to instantiate arbitrary utility classes within the Twig environment.

While this feature is intended to increase template flexibility, it introduces a significant attack surface by exposing direct object instantiation capabilities to template authors. To prevent abuse, such as remote command execution or file system manipulation, the helper relies on an explicit blocklist of forbidden classes. However, if a dangerous class is omitted from this blocklist, any user capable of writing or modifying non-sandboxed templates can instantiate that class and interact with its methods.

This specific vulnerability is classified under CWE-470 (Use of Externally-Controlled Input to Select Classes or Code, or 'Unsafe Reflection'). Because the class dynamic creation mechanism did not fully restrict access to file-handling classes, it allowed authenticated users with template-authoring permissions to read arbitrary local files, including confidential configuration keys, via standard PHP object manipulation interfaces.

Root Cause Analysis

The underlying vulnerability is located within the createFunction() method inside the custom Twig extension class (src/web/twig/Extension.php). This method accepts a class name identifier as a string and an optional array of parameters, which are then used to dynamically instantiate the specified object using reflection or standard PHP instantiation routines.

To restrict the instantiation of dangerous classes, the method utilizes a blocklist array containing classes known to pose security risks. The original implementation of this blocklist included Symfony\Component\Process\Process (to prevent command injection), GuzzleHttp\Psr7\FnStream (to prevent stream abuse), and SimpleXMLElement (to prevent XML External Entity injection). However, it failed to block SplFileObject, which is a built-in PHP class representing a local file stream.

Because SplFileObject implements PHP's SeekableIterator, RecursiveIterator, and IteratorAggregate interfaces, it behaves as an iterable collection of file lines. When an attacker passes SplFileObject as the target class to the create() helper, the PHP interpreter instantiates the object and opens a read stream to the file path provided in the parameters. This allows the template engine to bypass standard path restrictions and access files directly on the host system.

Code-Level Diff & Patch Analysis

The vulnerability was mitigated by adding SplFileObject directly to the class blocklist within src/web/twig/Extension.php across both the 4.x and 5.x maintenance branches. This prevents the dynamic instantiation helper from processing any request to create an instance of this file-handling class.

Below is the code-level change applied in the 5.x branch to restrict the instantiation of SplFileObject:

File: src/web/twig/Extension.php
@@ -73,6 +73,7 @@
 use IteratorAggregate;
 use Money\Money;
 use SimpleXMLElement;
+use SplFileObject;
 use Symfony\Component\Process\Process;
 use Throwable;
 use Traversable;
@@ -1552,6 +1553,7 @@ public function createFunction(string|array $type, array $params = []): object
             FnStream::class,
             Process::class,
             SimpleXMLElement::class,
+            SplFileObject::class,
         ];
 
         foreach ($blocklist as $c) {

While this change successfully blocks SplFileObject, a blocklist-based approach remains structurally fragile compared to an allowlist. Third-party packages loaded via Composer into the vendor/ directory could introduce other classes that permit arbitrary file reading, server-side request forgery (SSRF), or deserialization. A robust remediation strategy would deprecate arbitrary dynamic class instantiation in template contexts entirely, or enforce a strict, closed allowlist of permitted utility classes.

Exploitation Methodology

To exploit this vulnerability, an attacker must first obtain credentials for an account with permissions to author or edit Twig templates that are evaluated in a non-sandboxed context. This access is typically restricted to administrators or highly privileged content managers who configure system templates, custom fields, or entry-type rendering options within the Craft CMS Control Panel.

Once the template-authoring interface is accessible, the attacker can inject a payload that leverages the create() helper. By specifying the string 'SplFileObject' as the first argument and an array containing the path to a sensitive local file as the second argument, the attacker forces the server to open the target file. The attacker then uses a standard Twig iteration loop ({% for %}) to read each line sequentially and render it to the output page.

The following Twig code snippet demonstrates a functional proof-of-concept payload designed to extract the database configurations and system security keys contained in the local environment file:

{# Craft CMS SplFileObject Arbitrary File Read PoC #}
{% set file = create('SplFileObject', ['.env']) %}
{% for line in file %}
    {{ line }}
{% endfor %}

Impact & Threat Assessment

The concrete security impact of this vulnerability is significant, as it permits unauthorized access to the application's environment configuration file (.env). The .env file in Craft CMS contains the primary database credentials, third-party API integration keys, SMTP server credentials, and the global application security key (CRAFT_SECURITY_KEY).

Acquiring the CRAFT_SECURITY_KEY represents a high-severity threat. The application uses this key to sign cookies, generate secure tokens, and encrypt serialized data. If an attacker recovers this key, they can craft valid cryptographic signatures to perform object deserialization attacks or forge administrative sessions, potentially escalating the initial information disclosure vulnerability into a remote code execution vector.

Additionally, on host operating systems where PHP file permissions are weak, this vulnerability can be leveraged to read sensitive system configuration files outside the web directory. For example, on standard Linux installations, an attacker could read /etc/passwd to enumerate local system users and facilitate targeted privilege escalation attacks.

Defensive Strategies & Remediation

The primary remediation for this vulnerability is to upgrade Craft CMS to a patched release. Organizations running the 4.x release line must update to version 4.18.2 or later. Organizations running the 5.x release line must update to version 5.10.6 or later. These updates modify the createFunction() blocklist to prevent the instantiation of SplFileObject and other related file system stream classes.

If patching cannot be executed immediately, administrators should implement defensive configuration controls. Restricting the PHP execution environment using the open_basedir directive in php.ini can limit the directories that PHP's file system classes are permitted to open. This prevents SplFileObject from accessing files outside of designated application paths, even if the blocklist bypass is exploited.

Furthermore, administrative template-authoring capabilities should be strictly restricted to trusted staff members. Organizations should regularly review user permissions to ensure that only authorized developers are granted access to write or modify custom Twig templates, thereby reducing the exposure of non-sandboxed template evaluation interfaces.

Official Patches

CraftCMSCraft CMS 4.18.2 Release Tag containing the security patch
CraftCMSCraft CMS 5.10.6 Release Tag containing the security patch

Fix Analysis (2)

Technical Appendix

CVSS Score
4.9/ 10

Affected Systems

Craft CMS 4.xCraft CMS 5.x

Affected Versions Detail

Product
Affected Versions
Fixed Version
Craft CMS
CraftCMS
>= 4.0.0, < 4.18.24.18.2
Craft CMS
CraftCMS
>= 5.0.0, < 5.10.65.10.6
AttributeDetail
CWE IDCWE-470
Attack VectorNetwork / Authenticated Administrative User
Vulnerability ClassUnsafe Reflection
CVSS Score4.9
Exploit Statuspoc
KEV Statusnot listed

MITRE ATT&CK Mapping

T1059.006Command and Scripting Interpreter: Astro/Twig/etc. (Template Engines)
Execution
T1552Unsecured Credentials
Credential Access
T1083File and Directory Discovery
Discovery
CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

The application uses externally-controlled input to select a class or code to instantiate, without sufficiently restricting which classes can be instantiated.

Known Exploits & Detection

GitHub Advisory DatabaseProof of concept using standard Twig iteration to leak the server .env file.

References & Sources

  • [1]GitHub Advisory: Craft CMS Arbitrary File Read
  • [2]Fix Commit (5.x Branch)
  • [3]Fix Commit (4.x Branch)

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•18 minutes ago•CVE-2026-105749
6.5

CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.

Amit Schendel
Amit Schendel
0 views•6 min read
•about 1 hour ago•CVE-2026-105748
4.3

CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser

A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.

Amit Schendel
Amit Schendel
3 views•5 min read
•about 2 hours ago•CVE-2026-105744
7.5

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 3 hours ago•CVE-2026-105743
4.0

CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine

An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 4 hours ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
5 views•6 min read
•about 5 hours ago•CVE-2026-106121
4.9

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Amit Schendel
Amit Schendel
7 views•6 min read