Incomplete List of Disallowed Inputs in Craft CMS - #VU139964

 

Incomplete List of Disallowed Inputs in Craft CMS - #VU139964

Published: July 29, 2026


Vulnerability identifier: #VU139964
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incomplete list of disallowed inputs in the create() Twig function when instantiating arbitrary PHP classes from non-sandboxed template contexts. A remote user can configure a crafted entry type title format using SplFileObject to disclose sensitive information.

Exploitation requires admin access to the control panel, allowAdminChanges to be enabled, and the ability to edit entry type settings. The issue does not affect sandboxed template contexts.


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - addressed in versions 4.18.2, 5.10.6

External References

Related Security Bulletins