Executive brief
Pico is a lightweight flat-file content management system used to host websites. An attacker can manipulate HTTP headers to trick Pico into loading malicious JavaScript and CSS files from attacker-controlled domains, potentially leading to session hijacking, credential theft, or malware distribution to site visitors.
Technical details
A host header injection vulnerability exists in the Pico::getBaseUrl() method in lib/Pico.php. When the base_url configuration is not set (the default), the code constructs the base URL from unvalidated HTTP request headers including Host, X-Forwarded-Host, X-Forwarded-Proto, and X-Forwarded-Port. An unauthenticated remote attacker can inject arbitrary host values via these headers to control the origin of JavaScript and CSS assets loaded by the default theme. This allows arbitrary script execution in the context of the victim's browser if the attacker can control a request to the vulnerable server (e.g., via reflected parameters or Host header manipulation). No authentication is required, and the attack is network-reachable.
Affected products
- picocms Pico through 2.1.4
Timeline
- 2026-08-10: disclosed