Kestrel
대시보드로 돌아가기
CVE-2026-55792MEDIUMMITRENVDGHSA대응게시일: 2026. 07. 01.수정일: 2026. 07. 06.

Craft CMS: Sensitive File Disclosure / Server-Side File Read

Info-Disclosure

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
medium

이론적 심각도 점수

EPSS
0.3%상위 81.3%

30일 내 악용 확률 예측

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

CVSS 벡터 정보 없음

상세 설명

The dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel user granted the utility:system-messages permission to embed a file-reading payload into system email templates. When those emails are sent, the server reads the target file and returns its contents as a base64-encoded data URL embedded in the email body. The .env file, which typically contains the database password, CRAFT_SECURITY_KEY, and third-party API keys, passes all of Craft’s existing dataUrl() protection checks and is fully exfiltrated. Obtaining CRAFT_SECURITY_KEY enables an attacker to forge session tokens and escalate to full admin account takeover.

Details

Affected versions: Craft CMS 4.x, 5.x (confirmed against 5.9.19)

The vulnerability arises from the combination of three code facts:

  1. dataUrl is in the Twig sandbox allowlist
    src/config/twig-sandbox.php, line 115:
    php'allowedFunctions' => [
    ...
    'dataUrl', // ← allows file reading inside sandboxed templates
    ...
    ],

  2. Html::dataUrl() does not block dotfiles
    src/helpers/Html.php, lines 1065–1090. The function applies four checks before reading a file:

Must be within the project root .env is at the root
Must not be in a system directory (config/, vendor/, storage/, templates/) .env is not
Must not be a .php file .env has no extension
File must exist .env always exists in a Craft install

There is no check for dotfiles or specifically for .env. All four checks pass silently and file_get_contents() is called, with the result returned as data:text/plain;base64,....

  1. System message body is rendered via renderSandboxedString()
    src/mail/Mailer.php, lines 181–183:
    php$subject = $view->renderSandboxedString($systemMessage->subject, $variables);
    $textBody = $view->renderSandboxedString($systemMessage->body, $variables);
    $htmlBody = $view->renderSandboxedString($systemMessage->body, $variables, escapeHtml: true);

Any body content saved to a system message is executed inside the Twig sandbox when the email renders. Because dataUrl is in allowedFunctions, the sandbox policy permits its execution without restriction.

Access control: The utility:system-messages permission is a non-admin CP permission grantable to any user group via Settings > Users > Groups. It is not restricted to admins.

Impact

Vulnerability type: Sensitive File Disclosure / Server-Side File Read
Who is impacted: Any Craft CMS 4.x or 5.x installation where at least one non-admin control panel user has been granted the utility:system-messages permission, and email sending is configured.

Resources:

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.