← Terug naar overzicht

CVE-2026-75574 affects the Grav Email plugin (getgrav/grav-plugin-email) prior to version 4.2.2. The vulnerability arises because page-editor-controlled Email action parameters are rendered as unsandboxed Twig templates. An authenticated remote attacker with only api.access and api.pages.write permissions can inject a malicious Twig expression into the header.form.process.email.body field of a page. By publishing the page and submitting the associated form, the attacker can trigger execution of arbitrary operating-system commands under the account running PHP. This represents a high-severity remote code execution vulnerability requiring only low-privilege authenticated access. Users are advised to upgrade to version 4.2.2 or later to remediate the issue.

Affected products

  • Grav Email Plugin (getgrav/grav-plugin-email) before 4.2.2

Related CVE's

  • CVE-2026-75574

Categories

  • Email & Messaging
  • Web Technologies
  • Zero-Day Vulnerabilities