GHSA-m5qg-jc75-4jp6
October Rain has a Twig Sandbox Bypass via Collection Methods
Quick fix
GHSA-m5qg-jc75-4jp6 — october/rain: upgrade to the fixed version with the command below.
composer require october/rain:^4.1.5Details
A sandbox bypass vulnerability was identified in the optional Twig safe mode feature (`CMS_SAFE_MODE`). Certain methods on the `collect()` helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections.
### Impact - Bypass of Twig sandbox restrictions - Only affects installations with `CMS_SAFE_MODE` enabled (disabled by default) - Requires authenticated backend access with CMS template editing permissions
### Patches The vulnerability has been patched in v4.1.5 and v3.7.13. All users who have enabled safe mode are encouraged to upgrade to the latest patched version.
### Workarounds If upgrading immediately is not possible: - Disable `CMS_SAFE_MODE` if untrusted template editing is not required - Restrict CMS template editing permissions to fully trusted administrators only
### References - Reported by Łukasz Rybak
Are you affected?
Enter the version of the package you're using.