Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using the unsandboxed find filter in email subject, body, to, or from fields to achieve remote code execution when forms are submitted.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Grav CMS versions before 2.0.13 suffer from a critical server-side template injection (SSTI) vulnerability in email-action parameters that directly impacts content management security. Low-privileged page editors can inject malicious Twig template code through email subject, body, to, and from fields, bypassing the sandbox protections that should restrict template operations. When forms are submitted, these unsanitized Twig payloads—particularly leveraging the unsandboxed find filter—execute with application privileges, enabling remote code execution on the underlying operating system. This vulnerability matters because it transforms a common CMS role (page editor) into a vector for complete system compromise, affecting any organization running vulnerable Grav instances for websites, portals, or content delivery platforms.
While MITRE ATT&CK techniques are not formally mapped to this CVE, Casky's extended reasoning capabilities would detect the attack chain across multiple security domains: Template Injection (CWE-1336), Code Injection patterns, and OS Command Execution. A practitioner using Casky would observe findings related to unsanitized user input flowing into template rendering engines, privilege escalation from editor to system-level execution, and the suspicious use of dangerous template filters in user-controlled fields. The platform's Claude-powered analysis would flag the critical gap between intended (formatting email fields) and actual behavior (arbitrary code execution), helping teams identify similar template injection patterns in their own applications before exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-72827. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation