{"id":"CVE-2026-61453","aliases":["GHSA-2c4f-86xc-cr74"],"url":"https://o3.security/vulnerability/CVE-2026-61453","summary":"Grav before 2.0.1 XSS via Twig String Concatenation","details":"Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig content processing is enabled (twig_content.process_enabled: true), an attacker with page-write API permission can use Twig's string concatenation operator (~) to dynamically construct event handler names, dangerous tag names, or dangerous protocols at render time (e.g. {% set x = \"on\" ~ \"error\" %}). The validator sees only the harmless Twig expression and allows the content, but after Twig rendering the output (rendered via {{ page.content|raw }}) contains an active payload such as <img src=1 onerror=alert(1)>, executing arbitrary JavaScript in visitors' browsers.","published":"2026-07-15T11:25:45.830Z","modified":"2026-08-12T03:51:17.110929407Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"2.0.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61453.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-2c4f-86xc-cr74"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61453"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/grav-before-xss-via-twig-string-concatenation"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:17.110929407Z"}}