CVE-2026-61451: URL Redirection to Untrusted Site ('Open Redirect') in getgrav grav
The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/https and never verifies the host against the server's own origin, so an attacker can supply an arbitrary host. As a result, an unauthenticated attacker can cause the password reset email sent to a victim to contain a reset link pointing at an attacker-controlled server; when the victim follows the link, the valid reset token is disclosed to the attacker, enabling full account takeover. The vulnerable base URL can also be influenced via the Referer or Origin headers.
AI Analysis
Technical Summary
The Grav API plugin (grav-plugin-api) prior to version 1.0.4 does not adequately validate the admin_base_url parameter in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http or https but does not verify that the host matches the server's origin. This allows an attacker to supply a URL pointing to an attacker-controlled domain. Consequently, password reset emails sent to victims contain reset links that redirect to attacker-controlled sites, exposing valid reset tokens. This vulnerability can be triggered by unauthenticated attackers and can also be influenced by Referer or Origin HTTP headers.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to cause password reset emails to contain links to attacker-controlled domains. When victims follow these links, their valid password reset tokens are disclosed to the attacker, enabling full account takeover. This represents a critical security risk affecting user account integrity and confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should monitor vendor communications for updates. Avoid using vulnerable versions of the Grav API plugin and consider restricting or validating the admin_base_url parameter at the application or network level if possible.
CVE-2026-61451: URL Redirection to Untrusted Site ('Open Redirect') in getgrav grav
Description
The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/https and never verifies the host against the server's own origin, so an attacker can supply an arbitrary host. As a result, an unauthenticated attacker can cause the password reset email sent to a victim to contain a reset link pointing at an attacker-controlled server; when the victim follows the link, the valid reset token is disclosed to the attacker, enabling full account takeover. The vulnerable base URL can also be influenced via the Referer or Origin headers.
CVSS v4.0
Score 9.4critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Grav API plugin (grav-plugin-api) prior to version 1.0.4 does not adequately validate the admin_base_url parameter in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http or https but does not verify that the host matches the server's origin. This allows an attacker to supply a URL pointing to an attacker-controlled domain. Consequently, password reset emails sent to victims contain reset links that redirect to attacker-controlled sites, exposing valid reset tokens. This vulnerability can be triggered by unauthenticated attackers and can also be influenced by Referer or Origin HTTP headers.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to cause password reset emails to contain links to attacker-controlled domains. When victims follow these links, their valid password reset tokens are disclosed to the attacker, enabling full account takeover. This represents a critical security risk affecting user account integrity and confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should monitor vendor communications for updates. Avoid using vulnerable versions of the Grav API plugin and consider restricting or validating the admin_base_url parameter at the application or network level if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-09T14:06:14.016Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a57772068715ace43a93bc7
Added to database: 07/15/2026, 12:03:44 UTC
Last enriched: 07/30/2026, 00:03:21 UTC
Last updated: 08/29/2026, 10:52:10 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.