CVE-2026-27933: Manyfold

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via cookie leakage in proxy caches. Version 0.133.0 fixes the issue.

Affected products

  • Manyfold Manyfold: before 0.133.0 (fixed in 0.133.0)

Published 2026-02-26. Last modified 2026-06-17.