Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/canhieu/cve-2026-100671-poc
Vulnerability AnalysisExploitationWeb Application ExploitationSecurity VirtualizationWeb SecurityPenetration Testing
GitHubcanhieu/cve-2026-100671-poc

cve-2026-100671-poc

Local-only proof-of-concept verifier for CVE-2026-100671, reproducing Grav Twig page-cache session-cookie disclosure and replay against loopback targets.

View Repository
62 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-100671 — Grav Twig session-cookie disclosure

Minimal, local-only verifier for the Grav content-Twig/page-cache session takeover fixed in Grav 2.0.25.

Advisories:

  • CVE-2026-100671
  • GHSA-pp89-h475-7gj6
  • Grav 2.0.25 release

Scope

exploit.py is deliberately restricted to loopback targets:

  • 127.0.0.1
  • ::1
  • localhost

It refuses remote hosts, follows only loopback redirects, uses Python standard library HTTP clients, applies request timeouts, and never prints bearer tokens, cookies, or response bodies.

Use only against a Grav instance that you own or are explicitly authorized to test. The script creates a public proof page in the local lab. Remove that page after testing if the lab keeps content between runs.

Vulnerability chain

  1. A low-privilege page writer publishes content containing sandboxed Twig.
  2. get_cookie() reads the visiting administrator's session cookie server-side.
  3. Grav stores the post-Twig page output in a cache without session identity.
  4. An unauthenticated request receives the cached cookie value.
  5. Replaying that value against the local API authenticates as the administrator.

The page-write account needs only the documented low-privilege write path. It does not need api.pages.read, admin.*, or super-admin access. The victim admin only needs to visit the public page once.

Affected versions

  • Grav 2.0.19 through 2.0.24: vulnerable with shipped default content-Twig configuration.
  • Grav 2.0.0 through 2.0.18, and 1.7.x: affected only when content Twig was explicitly enabled.
  • Grav 2.0.25: fixed.

Lab requirements

Run a local Grav lab with:

  • Grav API plugin enabled;
  • Grav Login plugin enabled;
  • one low-privilege writer account able to obtain an API token and create pages;
  • one administrator account;
  • the target page route publicly readable.

This two-file repository does not provision Grav, PHP, plugins, or accounts.

Run

Set credentials through environment variables so they never enter source control:

export GRAV_BASE_URL=http://127.0.0.1:8080
export GRAV_WRITER_USERNAME=low
export GRAV_WRITER_PASSWORD='local-writer-password'
export GRAV_ADMIN_USERNAME=admin
export GRAV_ADMIN_PASSWORD='local-admin-password'

python3 exploit.py

The base URL must remain loopback. The default route is random. A fixed route can be selected when comparing runs:

python3 exploit.py --route /cookie-proof-24

Expected vulnerable result:

page_create_status=201
admin_login_status=200
victim_page_status=200
attacker_page_status=200
cached_victim_cookie_visible_to_attacker=yes
admin_cookie_value_match=yes
replayed_cookie_api_status=200
result=VULNERABLE

The command exits 0 when the expected result is reproduced, 1 when it is not reproduced, and 2 for a setup or transport error.

Fixed-version check

Run the same command against Grav 2.0.25:

python3 exploit.py --expect fixed

Expected fixed behavior: no attacker-visible session value and no successful session replay. A clean fixed result exits 0 with --expect fixed.

Remediation

Upgrade to Grav 2.0.25 or later. For older deployments, the advisory lists these temporary controls:

  • disable content Twig with security.twig_content.process_enabled: false; or
  • set system.pages.never_cache_twig: true;
  • clear existing Grav caches;
  • rotate administrator sessions.

Do not treat HttpOnly, Secure, or SameSite as a fix: the vulnerable cookie read occurs server-side during Twig rendering.

Disclosure

Reported by canhieu. This repository is a reproducibility aid for the already-public advisory, not a remote scanner or a credential-harvesting tool.

Download Tool