CVE-2026-27933

M

anyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via cookie leakage in proxy caches. Version 0.133.0 fixes the issue.

Configurations

Configuration 1 (hide)

cpe:2.3:a:manyfold:manyfold:*:*:*:*:*:*:*:*

History

27 Feb 2026, 17:27

Type Values Removed Values Added
CPE cpe:2.3:a:manyfold:manyfold:*:*:*:*:*:*:*:*
First Time Manyfold manyfold
Manyfold
References () https://github.com/manyfold3d/manyfold/releases/tag/v0.133.0 - () https://github.com/manyfold3d/manyfold/releases/tag/v0.133.0 - Product, Release Notes
References () https://github.com/manyfold3d/manyfold/security/advisories/GHSA-g949-hmvj-2r76 - () https://github.com/manyfold3d/manyfold/security/advisories/GHSA-g949-hmvj-2r76 - Exploit, Vendor Advisory

26 Feb 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 00:16

Updated : 2026-02-27 17:27


NVD link : CVE-2026-27933

Mitre link : CVE-2026-27933

CVE.ORG link : CVE-2026-27933


JSON object : View

Products Affected
CWE
CWE-613

Insufficient Session Expiration