GHSA-m59h-42jf-cphr
Sprig Plugin for Craft CMS potentially discloses sensitive information via Sprig Playground
Quick fix
GHSA-m59h-42jf-cphr — putyourlightson/craft-sprig: upgrade to the fixed version with the command below.
composer require putyourlightson/craft-sprig:^2.15.2Details
Admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive configuration data, in addition to running the `hashData()` signing function.
This issue was mitigated in versions 3.7.2 and 2.15.2 by disabling access to the Sprig Playground entirely when `devMode` is disabled, by default. It is possible to override this behaviour using a new `enablePlaygroundWhenDevModeDisabled` that defaults to `false`.
References:
- https://github.com/putyourlightson/craft-sprig/commit/db18c46f6dc5603828aa321a3a615adbd677d475 - https://github.com/putyourlightson/craft-sprig/commit/09c9da2ffb45a8857829f3390ae2578e26cfe03b
Are you affected?
Enter the version of the package you're using.
Affected packages
2.0.0Fixed in: 2.15.2composer require putyourlightson/craft-sprig:^2.15.23.0.0Fixed in: 3.7.2composer require putyourlightson/craft-sprig:^3.7.2References
- https://github.com/putyourlightson/craft-sprig/security/advisories/GHSA-m59h-42jf-cphr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-27131[ADVISORY]
- https://github.com/putyourlightson/craft-sprig/commit/09c9da2ffb45a8857829f3390ae2578e26cfe03b[WEB]
- https://github.com/putyourlightson/craft-sprig/commit/db18c46f6dc5603828aa321a3a615adbd677d475[WEB]
- https://github.com/putyourlightson/craft-sprig[PACKAGE]