CVE-2026-27933

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via cookie leakage in proxy caches. Version 0.133.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:manyfold:manyfold:*:*:*:*:*:*:*:*

History

27 Feb 2026, 17:27

Type Values Removed Values Added
First Time Manyfold manyfold
Manyfold
References () https://github.com/manyfold3d/manyfold/releases/tag/v0.133.0 - () https://github.com/manyfold3d/manyfold/releases/tag/v0.133.0 - Product, Release Notes
References () https://github.com/manyfold3d/manyfold/security/advisories/GHSA-g949-hmvj-2r76 - () https://github.com/manyfold3d/manyfold/security/advisories/GHSA-g949-hmvj-2r76 - Exploit, Vendor Advisory
CPE cpe:2.3:a:manyfold:manyfold:*:*:*:*:*:*:*:*

26 Feb 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 00:16

Updated : 2026-02-27 17:27


NVD link : CVE-2026-27933

Mitre link : CVE-2026-27933

CVE.ORG link : CVE-2026-27933


JSON object : View

Products Affected

manyfold

  • manyfold
CWE
CWE-613

Insufficient Session Expiration