Vulnerability Description
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getgrav | Grav | < 1.7.49.5 |
Related Weaknesses (CWE)
References
- https://github.com/Yohane-Mashiro/grav_cve/issues/2ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2025-66844?
CVE-2025-66844 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be reg...
How severe is CVE-2025-66844?
CVE-2025-66844 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-66844?
Check the references section above for vendor advisories and patch information. Affected products include: Getgrav Grav.