wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xf64-4pmc-h8qf wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Wger-project
Wger-project wger
Vendors & Products Wger-project
Wger-project wger

Wed, 07 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.
Title wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T17:04:45.845Z

Reserved: 2026-05-08T20:44:38.965Z

Link: CVE-2026-45161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-07T14:17:10.087

Modified: 2026-10-07T17:16:55.703

Link: CVE-2026-45161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T15:45:06Z

Weaknesses