{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-27131",
        "tracking": {
            "current_release_date": "2026-03-30T14:40:43.449323Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-27131",
            "initial_release_date": "2026-03-24T14:24:44.765804Z",
            "revision_history": [
                {
                    "date": "2026-03-24T14:24:44.765804Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T14:24:55.094151Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-24T17:15:16.867400Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T17:15:23.431619Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:49:43.834030Z",
                    "number": "5",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-24T21:48:33.005079Z",
                    "number": "6",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-24T21:48:40.427571Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T01:00:27.056838Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-25T01:00:32.654978Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T18:31:26.331580Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (47).| Product Identifiers created (47).| Products connected (2).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-25T18:31:33.012360Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T21:01:57.547974Z",
                    "number": "12",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-26T00:48:47.961561Z",
                    "number": "13",
                    "summary": "Products created (1).| Products removed (2).| References created (1)."
                },
                {
                    "date": "2026-03-30T14:40:30.112969Z",
                    "number": "14",
                    "summary": "Description removed for source.| Description created for source."
                },
                {
                    "date": "2026-03-30T14:40:32.742244Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "15"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.0",
                                "product": {
                                    "name": "vers:unknown/2.0.0",
                                    "product_id": "CSAFPID-5907885",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.1",
                                "product": {
                                    "name": "vers:unknown/2.0.1",
                                    "product_id": "CSAFPID-5907886",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0",
                                "product": {
                                    "name": "vers:unknown/2.1.0",
                                    "product_id": "CSAFPID-5907887",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.10.0",
                                "product": {
                                    "name": "vers:unknown/2.10.0",
                                    "product_id": "CSAFPID-5907888",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.10.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.10.1",
                                "product": {
                                    "name": "vers:unknown/2.10.1",
                                    "product_id": "CSAFPID-5907889",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.10.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.11.0",
                                "product": {
                                    "name": "vers:unknown/2.11.0",
                                    "product_id": "CSAFPID-5907890",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.11.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.12.0",
                                "product": {
                                    "name": "vers:unknown/2.12.0",
                                    "product_id": "CSAFPID-5907891",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.12.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.13.0",
                                "product": {
                                    "name": "vers:unknown/2.13.0",
                                    "product_id": "CSAFPID-5907892",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.13.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.13.1",
                                "product": {
                                    "name": "vers:unknown/2.13.1",
                                    "product_id": "CSAFPID-5907893",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.13.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.14.0",
                                "product": {
                                    "name": "vers:unknown/2.14.0",
                                    "product_id": "CSAFPID-5907894",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.14.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.14.1",
                                "product": {
                                    "name": "vers:unknown/2.14.1",
                                    "product_id": "CSAFPID-5907895",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.14.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.15.0",
                                "product": {
                                    "name": "vers:unknown/2.15.0",
                                    "product_id": "CSAFPID-5907896",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.15.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.15.1",
                                "product": {
                                    "name": "vers:unknown/2.15.1",
                                    "product_id": "CSAFPID-5907897",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.15.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.0",
                                "product": {
                                    "name": "vers:unknown/2.2.0",
                                    "product_id": "CSAFPID-5907898",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.1",
                                "product": {
                                    "name": "vers:unknown/2.2.1",
                                    "product_id": "CSAFPID-5907899",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.2.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.0",
                                "product": {
                                    "name": "vers:unknown/2.3.0",
                                    "product_id": "CSAFPID-5907900",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4.0",
                                "product": {
                                    "name": "vers:unknown/2.4.0",
                                    "product_id": "CSAFPID-5907901",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.4.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.0",
                                "product": {
                                    "name": "vers:unknown/2.5.0",
                                    "product_id": "CSAFPID-5907902",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.5.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.1",
                                "product": {
                                    "name": "vers:unknown/2.5.1",
                                    "product_id": "CSAFPID-5907903",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.5.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.0",
                                "product": {
                                    "name": "vers:unknown/2.6.0",
                                    "product_id": "CSAFPID-5907904",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.6.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.1",
                                "product": {
                                    "name": "vers:unknown/2.6.1",
                                    "product_id": "CSAFPID-5907905",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.6.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.2",
                                "product": {
                                    "name": "vers:unknown/2.6.2",
                                    "product_id": "CSAFPID-5907906",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.6.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.0",
                                "product": {
                                    "name": "vers:unknown/2.7.0",
                                    "product_id": "CSAFPID-5907907",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.7.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.1",
                                "product": {
                                    "name": "vers:unknown/2.7.1",
                                    "product_id": "CSAFPID-5907908",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.7.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.2",
                                "product": {
                                    "name": "vers:unknown/2.7.2",
                                    "product_id": "CSAFPID-5907909",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.7.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.3",
                                "product": {
                                    "name": "vers:unknown/2.7.3",
                                    "product_id": "CSAFPID-5907910",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.7.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.8.0",
                                "product": {
                                    "name": "vers:unknown/2.8.0",
                                    "product_id": "CSAFPID-5907911",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.8.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.8.1",
                                "product": {
                                    "name": "vers:unknown/2.8.1",
                                    "product_id": "CSAFPID-5907912",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.8.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.0",
                                "product": {
                                    "name": "vers:unknown/2.9.0",
                                    "product_id": "CSAFPID-5907913",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.9.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.0-beta.1",
                                "product": {
                                    "name": "vers:unknown/2.9.0-beta.1",
                                    "product_id": "CSAFPID-5907914",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@2.9.0-beta.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.0",
                                "product": {
                                    "name": "vers:unknown/3.0.0",
                                    "product_id": "CSAFPID-5907868",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.1",
                                "product": {
                                    "name": "vers:unknown/3.0.1",
                                    "product_id": "CSAFPID-5907869",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.2",
                                "product": {
                                    "name": "vers:unknown/3.0.2",
                                    "product_id": "CSAFPID-5907870",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.0",
                                "product": {
                                    "name": "vers:unknown/3.1.0",
                                    "product_id": "CSAFPID-5907871",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.0-beta.1",
                                "product": {
                                    "name": "vers:unknown/3.1.0-beta.1",
                                    "product_id": "CSAFPID-5907872",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.1.0-beta.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.2.0",
                                "product": {
                                    "name": "vers:unknown/3.2.0",
                                    "product_id": "CSAFPID-5907873",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.2.1",
                                "product": {
                                    "name": "vers:unknown/3.2.1",
                                    "product_id": "CSAFPID-5907874",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.2.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.3.0",
                                "product": {
                                    "name": "vers:unknown/3.3.0",
                                    "product_id": "CSAFPID-5907875",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.4.0",
                                "product": {
                                    "name": "vers:unknown/3.4.0",
                                    "product_id": "CSAFPID-5907876",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.4.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.5.0",
                                "product": {
                                    "name": "vers:unknown/3.5.0",
                                    "product_id": "CSAFPID-5907877",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.5.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.5.1",
                                "product": {
                                    "name": "vers:unknown/3.5.1",
                                    "product_id": "CSAFPID-5907878",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.5.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.5.2",
                                "product": {
                                    "name": "vers:unknown/3.5.2",
                                    "product_id": "CSAFPID-5907879",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.5.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.6.0",
                                "product": {
                                    "name": "vers:unknown/3.6.0",
                                    "product_id": "CSAFPID-5907880",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.6.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.6.1",
                                "product": {
                                    "name": "vers:unknown/3.6.1",
                                    "product_id": "CSAFPID-5907881",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.6.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.7.0",
                                "product": {
                                    "name": "vers:unknown/3.7.0",
                                    "product_id": "CSAFPID-5907882",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.7.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.7.1",
                                "product": {
                                    "name": "vers:unknown/3.7.1",
                                    "product_id": "CSAFPID-5907883",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/putyourlightson/craft-sprig@3.7.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.0.0|<2.15.2",
                                "product": {
                                    "name": "vers:unknown/>=2.0.0|<2.15.2",
                                    "product_id": "CSAFPID-5900021"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.0.0|<3.15.2",
                                "product": {
                                    "name": "vers:unknown/>=3.0.0|<3.15.2",
                                    "product_id": "CSAFPID-5900020"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.0.0|<3.7.2",
                                "product": {
                                    "name": "vers:unknown/>=3.0.0|<3.7.2",
                                    "product_id": "CSAFPID-5913503"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "craft-sprig"
                    }
                ],
                "category": "vendor",
                "name": "putyourlightson"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-27131",
            "cwe": {
                "id": "CWE-489",
                "name": "Active Debug Code"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive configuration data, in addition to running the `hashData()` signing function. This issue was mitigated in versions 3.15.2 and 2.15.2 by disabling access to the Sprig Playground entirely when `devMode` is disabled, by default. It is possible to override this behavior using a new `enablePlaygroundWhenDevModeDisabled` that defaults to `false`.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/27xxx/CVE-2026-27131.json"
                },
                {
                    "category": "description",
                    "text": "The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive configuration data, in addition to running the `hashData()` signing function. This issue was mitigated in versions 3.15.2 and 2.15.2 by disabling access to the Sprig Playground entirely when `devMode` is disabled, by default. It is possible to override this behavior using a new `enablePlaygroundWhenDevModeDisabled` that defaults to `false`.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27131"
                },
                {
                    "category": "description",
                    "text": "Admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive configuration data, in addition to running the `hashData()` signing function.\n\nThis issue was mitigated in versions 3.15.2 and 2.15.2 by disabling access to the Sprig Playground entirely when `devMode` is disabled, by default. It is possible to override this behaviour using a new `enablePlaygroundWhenDevModeDisabled` that defaults to `false`.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-m59h-42jf-cphr.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive configuration data, in addition to running the `hashData()` signing function.\n\nThis issue was mitigated in versions 3.7.2 and 2.15.2 by disabling access to the Sprig Playground entirely when `devMode` is disabled, by default. It is possible to override this behaviour using a new `enablePlaygroundWhenDevModeDisabled` that defaults to `false`.\n\nReferences:\n\n- https://github.com/putyourlightson/craft-sprig/commit/db18c46f6dc5603828aa321a3a615adbd677d475\n- https://github.com/putyourlightson/craft-sprig/commit/09c9da2ffb45a8857829f3390ae2578e26cfe03b",
                    "title": "github - https://api.github.com/advisories/GHSA-m59h-42jf-cphr"
                },
                {
                    "category": "other",
                    "text": "0.00028",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.0",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score, There is cwe data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5900020",
                    "CSAFPID-5900021",
                    "CSAFPID-5907868",
                    "CSAFPID-5907869",
                    "CSAFPID-5907870",
                    "CSAFPID-5907871",
                    "CSAFPID-5907872",
                    "CSAFPID-5907873",
                    "CSAFPID-5907874",
                    "CSAFPID-5907875",
                    "CSAFPID-5907876",
                    "CSAFPID-5907877",
                    "CSAFPID-5907878",
                    "CSAFPID-5907879",
                    "CSAFPID-5907880",
                    "CSAFPID-5907881",
                    "CSAFPID-5907882",
                    "CSAFPID-5907883",
                    "CSAFPID-5907885",
                    "CSAFPID-5907886",
                    "CSAFPID-5907887",
                    "CSAFPID-5907888",
                    "CSAFPID-5907889",
                    "CSAFPID-5907890",
                    "CSAFPID-5907891",
                    "CSAFPID-5907892",
                    "CSAFPID-5907893",
                    "CSAFPID-5907894",
                    "CSAFPID-5907895",
                    "CSAFPID-5907896",
                    "CSAFPID-5907897",
                    "CSAFPID-5907898",
                    "CSAFPID-5907899",
                    "CSAFPID-5907900",
                    "CSAFPID-5907901",
                    "CSAFPID-5907902",
                    "CSAFPID-5907903",
                    "CSAFPID-5907904",
                    "CSAFPID-5907905",
                    "CSAFPID-5907906",
                    "CSAFPID-5907907",
                    "CSAFPID-5907908",
                    "CSAFPID-5907909",
                    "CSAFPID-5907910",
                    "CSAFPID-5907911",
                    "CSAFPID-5907912",
                    "CSAFPID-5907913",
                    "CSAFPID-5907914",
                    "CSAFPID-5913503"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/27xxx/CVE-2026-27131.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27131"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-m59h-42jf-cphr"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-m59h-42jf-cphr.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/putyourlightson/craft-sprig/security/advisories/GHSA-m59h-42jf-cphr"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/putyourlightson/craft-sprig/commit/09c9da2ffb45a8857829f3390ae2578e26cfe03b"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/putyourlightson/craft-sprig/commit/db18c46f6dc5603828aa321a3a615adbd677d475"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-m59h-42jf-cphr"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27131"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-5900020",
                        "CSAFPID-5900021",
                        "CSAFPID-5907868",
                        "CSAFPID-5907869",
                        "CSAFPID-5907870",
                        "CSAFPID-5907871",
                        "CSAFPID-5907872",
                        "CSAFPID-5907873",
                        "CSAFPID-5907874",
                        "CSAFPID-5907875",
                        "CSAFPID-5907876",
                        "CSAFPID-5907877",
                        "CSAFPID-5907878",
                        "CSAFPID-5907879",
                        "CSAFPID-5907880",
                        "CSAFPID-5907881",
                        "CSAFPID-5907882",
                        "CSAFPID-5907883",
                        "CSAFPID-5907885",
                        "CSAFPID-5907886",
                        "CSAFPID-5907887",
                        "CSAFPID-5907888",
                        "CSAFPID-5907889",
                        "CSAFPID-5907890",
                        "CSAFPID-5907891",
                        "CSAFPID-5907892",
                        "CSAFPID-5907893",
                        "CSAFPID-5907894",
                        "CSAFPID-5907895",
                        "CSAFPID-5907896",
                        "CSAFPID-5907897",
                        "CSAFPID-5907898",
                        "CSAFPID-5907899",
                        "CSAFPID-5907900",
                        "CSAFPID-5907901",
                        "CSAFPID-5907902",
                        "CSAFPID-5907903",
                        "CSAFPID-5907904",
                        "CSAFPID-5907905",
                        "CSAFPID-5907906",
                        "CSAFPID-5907907",
                        "CSAFPID-5907908",
                        "CSAFPID-5907909",
                        "CSAFPID-5907910",
                        "CSAFPID-5907911",
                        "CSAFPID-5907912",
                        "CSAFPID-5907913",
                        "CSAFPID-5907914",
                        "CSAFPID-5913503"
                    ]
                }
            ],
            "title": "CVE-2026-27131"
        }
    ]
}