No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chaterm
Chaterm chaterm |
|
| Vendors & Products |
Chaterm
Chaterm chaterm |
Mon, 05 Oct 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the victim into the attacker's account so default data sync uploads saved hosts, passwords, and private keys. | |
| Title | Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T22:19:41.344Z
Reserved: 2026-10-05T00:18:59.611Z
Link: CVE-2026-105292
Updated: 2026-10-06T22:19:37.646Z
Status : Deferred
Published: 2026-10-05T01:16:28.630
Modified: 2026-10-06T23:16:56.197
Link: CVE-2026-105292
No data.
OpenCVE Enrichment
Updated: 2026-10-06T21:09:50Z