top of page
perceptive_background_267k.jpg

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenti…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 16:06:44

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Data Breach & Exfiltration

The Grav API plugin before v1.0.0-rc.16 contains a critical vulnerability where JWT tokens are accepted via the ?token= URL query parameter while the API responds with Access-Control-Allow-Origin: *, creating a dangerous CORS misconfiguration. This combination allows unauthenticated attackers to perform fully authenticated cross-origin API requests from any malicious website. JWT tokens can be harvested from access logs, proxy logs, browser history, or HTTP Referrer headers due to their exposure in URL query strings. Successful exploitation enables attackers to create persistent backdoor super-admin accounts, effectively achieving full administrative takeover of the Grav CMS instance. Sensitive configuration data and user data can also be exfiltrated. The vulnerability is particularly severe because it combines token leakage via URLs with a wildcard CORS policy, making exploitation straightforward. Users should upgrade to v1.0.0-rc.16 or later immediately.

Technical details

Mitigation steps:

Affected products:

Grav API plugin
Grav CMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page