When using encrypted LUKS devices as a disk being unlocked through a TPM device and grub fails to find a underlying filesytem, the boot manager will go into rescue mode and will still have the encryption key in memory. This allows an attacker with physical access to the target machine to access encrypted that through grub CLI which should not be accessible in this scenario.