Session Hijacking Vulnerability in Flarum Forum Software by Flarum
CVE-2025-27794
What is CVE-2025-27794?
Flarum forum software is susceptible to a session hijacking vulnerability which affects versions prior to 1.8.10. This issue arises when an attacker controls an authoritative subdomain that can set cookies for the parent domain. If session tokens are not rotated after authentication, an attacker could exploit this by replacing session tokens in sibling subdomains. To successfully execute this attack, the attacker must possess control over any subdomain of the parent domain, and the parent domain must not appear on the Public Suffix List. Although the theoretical reproduction of the issue seems feasible, current browser security measures limit actual exploitability. The vulnerability has been addressed in version 1.8.10.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
framework < 1.8.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
