What is CVE-2026-72574?
This is a host header injection vulnerability in picocms/Pico up to version 2.1.4, where an unauthenticated remote attacker can control the origin of loaded JavaScript and CSS assets via unvalidated Host headers when `base_url` is left unset. Since specific CVSS score, vendor details, or patched versions are not provided in the text, mitigation involves manually setting the `base_url` in Pico's configuration to prevent origin manipulation.
Azərbaycanca: Bu boşluq host header injection vasitəsilə picocms/Pico (2.1.4 versiyasına qədər) istifadəçilərinə təsir edir, autentifikasiya olunmamış uzaqdan hücumçuya JavaScript və CSS mənbələrinin yüklənmə mənşəyini idarə etməyə imkan verir. Mətndə qeyd olunmadığı üçün konkret CVSS balı, vendor detalları və ya yamaq versiyası təqdim edilmir, lakin təhlükəsizlik tədbiri kimi Pico konfiqurasiyasında `base_url` parametrinin əl ilə təyin edilməsi tövsiyə olunur.
FAQ2
Which versions of picocms/Pico are affected by the CVE-2026-72574 host header injection vulnerability?
This vulnerability affects picocms/Pico up to version 2.1.4.
What is the recommended mitigation for CVE-2026-72574?
The mitigation involves manually setting the `base_url` in Pico's configuration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.