Craft CMS: Authenticated leak of secret environment variables
Craft CMS contains a vulnerability where environment variables and secrets can be leaked by an authenticated attacker through interpolation in Twig templates, even when the Twig sandbox is enabled. The vulnerability arises because a request parameter allows environment variable references to be replaced before rendering, enabling incremental blind extraction of secrets. This can lead to privilege escalation and credential theft. The vulnerability requires authenticated access to the control panel and a large number of requests to exfiltrate secrets.
AI Analysis
Technical Summary
Craft CMS suffers from an authenticated information disclosure vulnerability (CVE-2026-31857) where environment variables and secrets are interpolated into Twig templates even when the sandbox is enabled. The parameter 'elementId' allows environment variable references in the form ${ENV_VAR} to be replaced with their values before the template is rendered. Although sandboxed Twig templates restrict direct access to environment variables and network functions, this interpolation bypasses those restrictions. An attacker with control panel access can use blind error-based techniques to incrementally leak secrets such as the CRAFT_SECURITY_KEY, database credentials, and API keys. This vulnerability enables session forgery, privilege escalation, and credential theft. The vulnerability is rated moderate severity and a patch is available.
Potential Impact
An authenticated attacker with control panel access can leak arbitrary environment variables and secrets by abusing the interpolation mechanism in Twig templates. This can lead to session forgery, privilege escalation, and theft of sensitive credentials including database, SMTP, and API keys. The attack requires many requests and blind error-based extraction techniques. The vulnerability undermines the security guarantees of the Twig sandbox and can compromise the confidentiality and integrity of the Craft CMS environment.
Mitigation Recommendations
A patch is available for this vulnerability. Users should apply the official fix provided by the Craft CMS vendor to prevent environment variable leakage via Twig template interpolation. Until patched, restricting control panel access and monitoring for suspicious template rendering activity may reduce risk. Verify that the Twig sandbox is enabled and updated to the fixed version. Check the vendor advisory for the latest remediation guidance.
Craft CMS: Authenticated leak of secret environment variables
Description
Craft CMS contains a vulnerability where environment variables and secrets can be leaked by an authenticated attacker through interpolation in Twig templates, even when the Twig sandbox is enabled. The vulnerability arises because a request parameter allows environment variable references to be replaced before rendering, enabling incremental blind extraction of secrets. This can lead to privilege escalation and credential theft. The vulnerability requires authenticated access to the control panel and a large number of requests to exfiltrate secrets.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Craft CMS suffers from an authenticated information disclosure vulnerability (CVE-2026-31857) where environment variables and secrets are interpolated into Twig templates even when the sandbox is enabled. The parameter 'elementId' allows environment variable references in the form ${ENV_VAR} to be replaced with their values before the template is rendered. Although sandboxed Twig templates restrict direct access to environment variables and network functions, this interpolation bypasses those restrictions. An attacker with control panel access can use blind error-based techniques to incrementally leak secrets such as the CRAFT_SECURITY_KEY, database credentials, and API keys. This vulnerability enables session forgery, privilege escalation, and credential theft. The vulnerability is rated moderate severity and a patch is available.
Potential Impact
An authenticated attacker with control panel access can leak arbitrary environment variables and secrets by abusing the interpolation mechanism in Twig templates. This can lead to session forgery, privilege escalation, and theft of sensitive credentials including database, SMTP, and API keys. The attack requires many requests and blind error-based extraction techniques. The vulnerability undermines the security guarantees of the Twig sandbox and can compromise the confidentiality and integrity of the Craft CMS environment.
Mitigation Recommendations
A patch is available for this vulnerability. Users should apply the official fix provided by the Craft CMS vendor to prevent environment variable leakage via Twig template interpolation. Until patched, restricting control panel access and monitoring for suspicious template rendering activity may reduce risk. Verify that the Twig sandbox is enabled and updated to the fixed version. Check the vendor advisory for the latest remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-596p-6jv8-775v
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a7573b9bf8831d539d940b3
Added to database: 08/07/2026, 05:57:13 UTC
Last enriched: 08/07/2026, 07:16:36 UTC
Last updated: 08/07/2026, 07:16:36 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.