
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27131 is an information disclosure vulnerability in the Sprig Plugin for Craft CMS, a reactive Twig component framework. Admin users and users with explicit permission to access the Sprig Playground could potentially expose the Craft CMS security key, credentials, and other sensitive configuration data, and could also invoke the hashData() signing function without appropriate restrictions. The vulnerability affects versions >= 2.0.0 and < 2.15.2 (v2 branch) and >= 3.0.0 and < 3.7.2 (v3 branch). It was disclosed on March 23, 2026, with patches released the same day. The CVSS v3.1 base score is 5.5 (Medium) (Github Advisory).
The root cause is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-489 (Active Debug Code), as the Sprig Playground — a developer-oriented feature — remained accessible in production environments when devMode was enabled, without adequate access restrictions (Github Advisory). The Playground feature allows execution of arbitrary Twig expressions, which can reference Craft CMS environment variables and configuration values including the application security key and database credentials. The fix introduced a getCanAccessPlayground() method in SettingsModel.php that gates Playground access on devMode being active, and added a new enablePlaygroundWhenDevModeDisabled configuration option (defaulting to false) to explicitly control this behavior (Commit 09c9da2, Commit db18c46). Exploitation requires high privileges (admin or explicit Playground permission), limiting the attack surface to trusted but potentially malicious insiders or compromised admin accounts.
Successful exploitation allows a privileged attacker to extract highly sensitive configuration data from the Craft CMS installation, including the application security key and database credentials (Github Advisory). Exposure of the security key could enable an attacker to forge signed data via the hashData() function, potentially undermining session integrity or other cryptographic protections within the application. While availability is not impacted, the confidentiality impact is rated High, and the integrity impact is rated Low due to the ability to run the signing function. The risk is most acute in production environments where devMode was inadvertently left enabled.
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.042% (13th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high privileges (admin-level access or explicit Playground permission), significantly reducing the likelihood of opportunistic attacks.
devMode enabled.enablePlayground is true and devMode is active.{{ craft.app.config.general.securityKey }} or similar expressions referencing database credentials.hashData() with attacker-controlled input to generate valid signed tokens, potentially enabling session forgery or other integrity attacks (Github Advisory)./sprig/playground) from unexpected users or at unusual times.securityKey, database credentials).hashData() signing function logged in Craft CMS audit logs, particularly from admin accounts not typically associated with development activity.Upgrade the Sprig Plugin to version 2.15.2 (for v2.x users) or version 3.7.2 (for v3.x users), which disable Playground access by default when devMode is not enabled (Github Advisory). As an immediate workaround for systems that cannot be patched, ensure devMode is disabled in all production Craft CMS environments, which will prevent Playground access in patched versions and reduce exposure in unpatched ones. Additionally, review and restrict Sprig Playground permissions to only essential development personnel, and set the new enablePlaygroundWhenDevModeDisabled configuration option to false (the default in patched versions) to prevent accidental re-enablement (Commit 09c9da2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."