Medium severity5.4NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-72702
CVE-2026-72702
Description
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim site's origin (e.g. https://example.com.attacker.tld) can send a request with such a Referer to be treated as same-origin, bypassing the Referer-based origin check.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | < 2.0.16 | 2.0.16 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Grav CMS: Six Vulnerabilities Disclosed, Including Twig Sandbox Escapes and Secret LeaksVypr Intelligence · Aug 25, 2026