VDB
Sign up
MEDIUM4.9

GHSA-m5qg-jc75-4jp6

October Rain has a Twig Sandbox Bypass via Collection Methods

Quick fix

GHSA-m5qg-jc75-4jp6 — october/rain: upgrade to the fixed version with the command below.

composer require october/rain:^4.1.5

Details

A sandbox bypass vulnerability was identified in the optional Twig safe mode feature (`CMS_SAFE_MODE`). Certain methods on the `collect()` helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections.

### Impact - Bypass of Twig sandbox restrictions - Only affects installations with `CMS_SAFE_MODE` enabled (disabled by default) - Requires authenticated backend access with CMS template editing permissions

### Patches The vulnerability has been patched in v4.1.5 and v3.7.13. All users who have enabled safe mode are encouraged to upgrade to the latest patched version.

### Workarounds If upgrading immediately is not possible: - Disable `CMS_SAFE_MODE` if untrusted template editing is not required - Restrict CMS template editing permissions to fully trusted administrators only

### References - Reported by Łukasz Rybak

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/october/rain
Introduced in: 4.0.0Fixed in: 4.1.5
Fixcomposer require october/rain:^4.1.5
Packagist/october/rain
Introduced in: 0Fixed in: 3.7.13
Fixcomposer require october/rain:^3.7.13

References