CVE-2026-59713
🟡 Monitoruj
Podatność CSRF w Leantime umożliwia atakującym przejęcie sesji użytkowników.
CVSS
8.1
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-07-06 21:16:58 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-17 18:16:56 UTC |
Referencje
- https://github.com/Leantime/leantime ([email protected])
- https://github.com/Leantime/leantime/commit/9630eb7db682fb1b4e23cdabf3428d03ec6f5094 ([email protected])
- https://github.com/Leantime/leantime/issues/3535 ([email protected])
- https://www.vulncheck.com/advisories/leantime-oidc-login-csrf-via-unconditional-state-verification-stub ([email protected])