Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the victim into the attacker's account so default data sync uploads saved hosts, passwords, and private keys.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the victim into the attacker's account so default data sync uploads saved hosts, passwords, and private keys. | |
| Title | Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-05T00:44:18.046Z
Reserved: 2026-10-05T00:18:59.611Z
Link: CVE-2026-105292
No data.
Status : Received
Published: 2026-10-05T01:16:28.630
Modified: 2026-10-05T01:16:28.630
Link: CVE-2026-105292
No data.
OpenCVE Enrichment
Updated: 2026-10-05T02:30:08Z
Weaknesses