Bypassing Content Sandbox in Grav CMS via Twig Variables
A vulnerability in Grav CMS allows attackers with page-content edit access to read sensitive configuration data, including secrets, due to the way Twig variables are handled in the content sandbox.