PT-2026-60145 · Grav · Grav-Plugin-Api

·

CVE-2026-61451

·

Published

2026-07-15

·

Updated

2026-07-16

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions grav-plugin-api versions prior to 1.0.4
Description An unauthenticated attacker can cause a password reset email to contain a link pointing to a server under their control. This occurs because the sanitizeHttpUrl() function fails to verify the host against the server's own origin, checking only that the URL scheme is http or https. The issue exists in the 'POST /api/v1/auth/forgot-password' endpoint via the admin base url field, and can also be influenced by the Referer or Origin headers. If a victim follows the malicious link, the valid reset token is disclosed to the attacker, allowing for full account takeover.
Recommendations Update to version 1.0.4 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61451
GHSA-5XC4-J99P-CP4M

Affected Products

Grav-Plugin-Api