Exposure of Resource to Wrong Sphere in Craft CMS - #VU139967
Published: July 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive resources in the Twig template rendering functionality when processing a crafted `elementId` parameter that interpolates environment variable references. A remote user can render a malicious sandboxed Twig template and use repeated error-based requests to disclose sensitive information.
Exploitation requires permission to access the control panel and can occur even when the Twig sandbox is enabled through `enableTwigSandbox()`.