Description
This module exploits a Server-Side Template Injection (SSTI) vulnerability (CVE-2025-66294) in Grav CMS that allows bypassing the Twig sandbox to achieve remote code execution. The cleanDangerousTwig method uses weak regex that fails to sanitize nested Twig calls within the evaluate_twig function. To inject the payload, this module leverages CVE-2025-66301, a broken access control flaw that allows users with page editing privileges to modify the form's YAML frontmatter process section.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/grav_twig_ssti_sandbox_bypass_rcemsf undefined(grav_twig_ssti_sandbox_bypass_rce) > show actions ...actions...msf undefined(grav_twig_ssti_sandbox_bypass_rce) > set ACTION < action-name >msf undefined(grav_twig_ssti_sandbox_bypass_rce) > show options ...show and set options...msf undefined(grav_twig_ssti_sandbox_bypass_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub