Sceawere

Vulnerability Detail

CVE-2026-105292UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chaterm Login CSRF Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
17h ago
Vendor
chaterm
Product
Chaterm
Attack Type
Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the victim into the attacker's account so default data sync uploads saved hosts, passwords, and private keys.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-10-05T01:16:28.630Z",
  "pubdate": "2026-10-05T01:16:28.630Z",
  "executiveSummary": "Chaterm versions prior to 0.12.1 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability involving the application's authentication flow.\nThe flaw allows remote attackers to force an authenticated session by manipulating URI callbacks, specifically using the chaterm:// protocol handler.\nBy failing to validate OAuth state parameters, the application accepts arbitrary, attacker-controlled userInfo injected via malicious web pages.\nSuccessful exploitation results in unauthorized account association, where a victim is silently logged into an attacker-controlled account.\nThis impact is critical as it facilitates data exfiltration; the application's automatic synchronization feature subsequently uploads the victim's local sensitive information, including saved hosts, passwords, and private SSH/cryptographic keys, directly to the attacker's account.\nThis vulnerability requires no complex prerequisites beyond the victim visiting a malicious page while the application is installed, making it a high-risk vector for credential theft and persistent session hijacking.",
  "technicalDetails": "The root cause of the vulnerability lies in the improper implementation of the OAuth 2.0 flow within the Chaterm URI scheme handler. Specifically, the application fails to enforce state parameter validation when processing chaterm:// callbacks. The state parameter is a critical security mechanism designed to maintain the integrity of the request-response cycle and prevent CSRF by ensuring that the callback received is a direct result of a request initiated by the legitimate user session.\nIn the vulnerable versions, the application blindly parses and trusts the userInfo object contained within the incoming URI callback. An attacker can craft a malicious web page that triggers a chaterm:// link containing a predefined, attacker-owned account token. When a user with the Chaterm application installed visits this page, the browser invokes the application via the registered protocol handler. Because the application lacks a cryptographically secure validation check for the OAuth state, it processes the attacker's payload as a valid authentication response.\nThe attack flow follows a deterministic pattern: 1) The attacker configures a malicious server or web page hosting the crafted URI. 2) The victim, who is a legitimate user of Chaterm, navigates to the malicious page. 3) The page triggers the chaterm:// callback, embedding the attacker's session identifiers within the URI. 4) Chaterm receives the callback, fails to perform an origin or state validation, and interprets the malicious payload as a legitimate login success. 5) The application updates its local authentication state, effectively signing the victim's client into the attacker's account. 6) Once the local session is associated with the attacker's account, the application's background synchronization service is triggered. This service automatically performs a data sync, exfiltrating the victim's saved hosts, stored passwords, and private keys to the cloud storage associated with the attacker's account, granting the attacker full access to the victim's sensitive infrastructure credentials."
}
CVE-2026-105292: Chaterm Login CSRF Vulnerability (MEDIUM Severity, CVSS: 5.9) | Sceawere