CVE-2026-27933 PUBLISHED

Manyfold vulnerable to session hijack via cookie leakage in proxy caches

Assigner: GitHub_M
Reserved: 25.02.2026 Published: 25.02.2026 Updated: 25.02.2026

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via cookie leakage in proxy caches. Version 0.133.0 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS Score: 6.8

Product Status

Vendor manyfold3d
Product manyfold
Versions
  • Version < 0.133.0 is affected

References

Problem Types

  • CWE-613: Insufficient Session Expiration CWE