Executive brief
Grav API Plugin provides headless access to Grav CMS content via a REST API. Prior to version 1.0.0-rc.16, the plugin's CORS middleware allows any website to make authenticated requests to the API if an attacker obtains a valid JWT token, enabling unauthorized data access and account modification. This could allow attackers to exfiltrate sensitive content or modify site data without direct server access.
Technical details
The vulnerability stems from two intersecting flaws in the Grav API Plugin: (1) overly permissive CORS headers that return Access-Control-Allow-Origin: * for authenticated API endpoints, and (2) JWT token handling that accepts tokens in URL query parameters (?token=) across all request methods. An attacker with a stolen or leaked JWT token can craft a malicious webpage that uses JavaScript to submit cross-origin requests to authenticated /api/v1 endpoints, bypass CORS protections, and perform API operations (read and write) with the token owner's privileges. The attack vector is network-based, requires knowledge of a valid JWT token, and exploits browser same-origin policy bypass. Version 1.0.0-rc.16 fixes this by restricting CORS to same-origin by default, honoring '*' only for unauthenticated responses, and limiting URL-based token parameters to safe GET/HEAD requests on file-streaming routes only.
Affected products
- getgrav API Plugin before 1.0.0-rc.16
Timeline
- 2026-08-19: disclosed
- 2026-06-19: patched: version 1.0.0-rc.16 released