Executive brief
The Grav API plugin, used to provide programmatic access to the Grav content management system, contained a security misconfiguration that allowed any website to interact with the API. If an attacker manages to obtain a user's access token through other means (such as browser history or server logs), they could use a malicious website to steal sensitive data or perform unauthorized actions on the user's behalf. This could lead to full account takeover or unauthorized modification of website content and configurations.
Technical details
The Grav API plugin (getgrav/grav-plugin-api) implemented a default CORS policy that returned 'Access-Control-Allow-Origin: *' on all responses, including those requiring authentication. While browsers typically restrict credentialed requests (cookies) when a wildcard origin is used, this plugin utilizes 'Authorization' and 'X-API-Token' headers which can be set programmatically via JavaScript. Consequently, if an attacker obtains a valid JWT or API token (via log leakage, Referer headers, or network capture), they can execute cross-origin fetch requests from a malicious domain to read sensitive API data or perform write operations (e.g., creating backdoor admin accounts). The vulnerability is fixed in version 1.0.0-rc.16.
Affected products
- getgrav Grav API plugin < 1.0.0-rc.16
Timeline
- 2026-06-30: advisory: Vendor advisory published on GitHub
- 2026-07-16: disclosed: NVD and VulnCheck publication