A AegiFlow
CRITICALCVSS 9.3EPSS 0.1%

CVE-2026-72702

CVE-2026-72702 updated by NVD

Published
2026-09-17
Modified
2026-09-17
EPSS percentile
1%
Sources
github-advisory, nvd

Summary

Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim site's origin (e.g. https://example.com.attacker.tld) can send a request with such a Referer to be treated as same-origin, bypassing the Referer-based origin check.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistgetgrav/grav2.0.16

Remediation: Upgrade to 2.0.16 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.