grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are evaluated at render time.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-75829 is a server-side template injection (SSTI) vulnerability in grav-plugin-api versions before 1.0.15 that stems from insufficient validation of Twig content in the translate() endpoint. Attackers with api.pages.write permissions can craft malicious header and content parameters to inject Twig template code that executes on the server during page rendering. This vulnerability affects Grav CMS installations using the vulnerable plugin version, particularly those exposing API endpoints to untrusted users or in multi-tenant environments where permission boundaries may be insufficiently enforced. The CVSS 8.1 score reflects the high severity of arbitrary code execution capabilities available to authenticated attackers.
While this CVE currently maps to zero Casky skills due to the novel nature of grav-plugin-api exploitation patterns, Claude AI's extended reasoning capabilities within the Casky platform would detect attack indicators aligned with MITRE ATT&CK's Execution and Persistence tactics. Practitioners using Casky would observe findings related to T1059 (Command and Scripting Interpreter) when template injection payloads attempt OS command execution, T1190 (Exploit Public-Facing Application) for API endpoint abuse, and T1608 (Artifact Staging) during payload preparation phases. Security teams should monitor for suspicious translate() endpoint requests containing template syntax, unexpected Twig directives in API payloads, and persistence of pages with process.twig enabled—patterns that Claude's reasoning would correlate as indicative of SSTI exploitation attempts targeting this specific vulnerability.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-75829. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation