{"id":"CVE-2026-28783","summary":"Craft has a Twig Function Blocklist Bypass","details":"Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack, you need to either have allowAdminChanges enabled on production, or a compromised admin account, or an account with access to the System Messages utility. Several PHP functions are not included in the blocklist, which could allow malicious actors with the required permissions to execute various types of payloads, including RCEs, arbitrary file reads, SSRFs, and SSTIs. This vulnerability is fixed in 5.9.0-beta.1 and 4.17.0-beta.1.","aliases":["GHSA-5fvc-7894-ghp4"],"modified":"2026-08-12T03:51:36.539570448Z","published":"2026-03-04T16:50:27.191Z","database_specific":{"cwe_ids":["CWE-1336","CWE-184","CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28783.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28783.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-5fvc-7894-ghp4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28783"},{"type":"FIX","url":"https://github.com/craftcms/cms/pull/18208"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/craftcms/cms","events":[{"introduced":"0"},{"fixed":"1c169ab8f76fcf73b828adb048b7b94f27a8a273"},{"fixed":"680259a1eef848ad601382e8b45a32d52f2d02b2"},{"introduced":"982efcd14d7e93a1a54f0905b61f242de6b53d8a"},{"last_affected":"04755d93f86d07cc183db47db8a0eee106892e30"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"4.17.0"},{"fixed":"5.9.0"},{"introduced":"4.0.0-NA"},{"last_affected":"4.0.0-NA"},{"introduced":"4.0.0-rc1"},{"last_affected":"4.0.0-rc1"},{"introduced":"4.0.0-rc2"},{"last_affected":"4.0.0-rc2"},{"introduced":"4.0.0-rc3"},{"last_affected":"4.0.0-rc3"},{"introduced":"5.0.0-NA"},{"last_affected":"5.0.0-NA"},{"introduced":"5.0.0-rc1"},{"last_affected":"5.0.0-rc1"}]}},{"type":"GIT","repo":"https://github.com/nystudio107/craft-seomatic","events":[{"introduced":"a31f7d211b52d55d274c66a291310ceec64c733f"},{"last_affected":"a31f7d211b52d55d274c66a291310ceec64c733f"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0-NA"},{"last_affected":"4.0.0-NA"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*"}}],"versions":["4.0.0-NA","4.0.0-rc1","4.0.0-rc2","4.0.0-rc3","5.0.0-NA","5.0.0-rc1","5.9.0-beta.2","4.17.0-beta.2","4.17.0-beta.1","5.9.0-beta.1","5.8.23","4.16.19","4.16.18","5.8.22","4.16.17","5.8.21","4.16.16","5.8.20","4.16.15","5.8.19","4.16.14","5.8.18","4.16.13","5.8.17","4.16.12","5.8.16","4.16.11","5.8.15","5.8.14","4.16.10","4.16.9.1","5.8.13.2","4.16.9","5.8.13.1","5.8.13","5.8.12","4.16.8","5.8.11","4.16.7","5.8.10","4.16.6.1","5.8.9","4.16.6","4.16.5","5.8.8","5.8.7","5.8.6","5.8.5","4.16.4","5.8.4","4.16.3","4.16.0","4.16.2","5.8.3","5.8.2","5.8.1","4.16.1","5.8.0","4.15.7","5.7.11","4.15.6.2","5.7.10","5.7.9","4.15.6.1","5.7.8.2","5.7.8.1","4.15.6","5.7.8","4.15.5","5.7.7","4.15.4","5.7.6","5.7.5","4.15.3","5.7.4","4.15.2","5.7.3","5.7.2","4.15.1","5.7.1.1","4.15.0.2","4.15.0.1","5.7.1","4.15.0","5.7.0","4.14.15","5.6.17","4.14.14","5.6.16","4.14.13","5.6.15","4.14.12","5.6.14","5.6.13","4.14.11.1","4.14.11","5.6.12","4.14.10","5.6.11","5.6.10.2","4.14.9","5.6.10.1","5.6.10","5.6.9.1","4.14.8.1","5.6.9","4.14.8","5.6.8","4.14.7","5.6.7","4.14.6","4.14.5","5.6.6","5.6.5.1","4.14.4","5.6.5","4.14.2","5.6.4","4.14.3","5.6.3","5.6.2","4.14.1","5.6.1","5.6.0.2","4.14.0.2","4.14.0","5.6.0.1","4.14.0.1","5.6.0","4.13.10","4.13.9","4.13.8","4.13.6","4.13.5","4.13.4","4.13.3","4.13.2","4.13.1.1","4.13.1","5.5.0.1","5.5.0","4.13.0","5.4.0","4.12.0","4.11.0.2","5.3.0.3","5.3.0.2","5.3.0.1","4.11.0.1","4.11.0","5.3.0","5.3.0-beta.1","5.3.0-beta.2","4.10.0-beta.2","5.2.0-beta.5","5.2.0-beta.4","5.2.0-beta.3","5.2.0-beta.2","4.10.0-beta.1","5.2.0-beta.1","4.8.11","4.8.10","4.8.9","4.8.8","4.8.7","4.8.6","5.0.0-RC1","5.0.0-beta.11","5.0.0-beta.10","5.0.0-beta.9","5.0.0-beta.8","5.0.0-beta.7","5.0.0-beta.6","5.0.0-beta.5","5.0.0-beta.4","5.0.0-beta.3","5.0.0-beta.2","5.0.0-beta.1","5.0.0-alpha.13","5.0.0-alpha.12","5.0.0-alpha.11","5.0.0-alpha.10","5.0.0-alpha.9","5.0.0-alpha.7","5.0.0-alpha.8","5.0.0-alpha.5","5.0.0-alpha.6","5.0.0-alpha.4","5.0.0-alpha.3","5.0.0-alpha.2","5.0.0-alpha.1","@craftcms/webpack@0.3.0","@craftcms/webpack@0.2.0","@craftcms/sass@1.0.1","@craftcms/webpack@0.0.1","@craftcms/sass@1.0.0","3.0.0-alpha.2948","3.0.0-alpha.2942","3.0.0-alpha.2939","3.0.0-alpha.2937","3.0.0-alpha.2933","3.0.0-alpha.2928","3.0.0-alpha.2918","3.0.0-alpha.2915","3.0.0-alpha.2687","3.0.0-alpha.2681","3.0.0-alpha.2671","2.3.2617","2.3.2616","2.3.2615","2.3.0-alpha.2612","2.3.0-alpha.2610","2.3.0-alpha.2608","2.3.0-alpha.2606","2.3.0-alpha.2605","2.3.0-alpha.2603","2.3.0-alpha.2602","2.3.0-alpha.2600","2.2.2581","2.2.2579","2.2.0-alpha.2578","2.1.2557","2.1.2556","2.1.2555","2.1.2554","2.1.0-alpha.2552","2.1.0-alpha.2547","2.1.0-alpha.2546","2.0.2539","2.0.2538","2.0.2537","2.0.2536","2.0.2535","2.0.2533","2.0.2532","2.0.2527","2.0.2525","2.0.2524","1.4.0-alpha.2509","1.4.0-alpha.2505","1.4.0-alpha.2503","1.4.0-alpha.2502","1.4.0-alpha.2500","1.4.0-alpha.2499","1.4.0-alpha.2498","1.4.0-alpha.2497","1.4.0-alpha.2493","1.4.0-alpha.2492","1.4.0-alpha.2491","1.4.0-alpha.2490","1.4.0-alpha.2489","1.4.0-alpha.2488","1.2.2339","1.2.2336","1.2.2335","1.2.2333","1.2.0-alpha.2329","1.2.0-alpha.2328","1.2.0-alpha.2322","1.2.0-alpha.2319","1.2.0-alpha.2318","1.2.0-alpha.2312","1.2.0-alpha.2310","1.1.2291","1.1.0-alpha.2288","1.1.0-alpha.2285","1.1.0-alpha.2284","1.1.0-alpha.2283","1.0.2266","1.0.0-alpha.2249","1.0.0-alpha.2248","1.0.0-alpha.2247","0.9.2246","1.0.0-alpha.2245","1.0.0-alpha.2244","0.9.2243","1.0.0-alpha.2242","1.0.0-alpha.2241","1.0.0-alpha.2238","1.0.0-alpha.2237","1.0.0-alpha.2236","0.9.2193","0.9.2189","0.9.2184","0.9.2181","0.9.2177","0.9.2168","0.9.2167","0.9.2157","0.9.2151","0.9.2146","0.9.2124","0.9.2123","0.9.2117","0.9.2116","0.9.2106","0.9.2102","0.9.2103","0.9.2101","0.9.2100","0.9.2094","0.9.2090","0.9.2083","0.9.2081","0.9.2080","0.9.2079","0.9.2078","0.9.2071","0.9.2068","0.9.2065","0.9.2064","0.9.2063","4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28783.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}