๐Ÿ” CVE Alert

CVE-2026-105292

MEDIUM 5.9

Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the victim into the attacker's account so default data sync uploads saved hosts, passwords, and private keys.

CWE CWE-352
Vendor chaterm
Product chaterm
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for chaterm chaterm

Be the first to know when new medium vulnerabilities affecting chaterm chaterm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

chaterm / Chaterm
0.2.0 < 0.12.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Chaterm/Chaterm/pull/2326 github.com: https://github.com/Chaterm/Chaterm/commit/41f747f17845cd980f289cc9ea8ff9978b6f7ad6 github.com: https://github.com/Chaterm/Chaterm github.com: https://github.com/Chaterm/Chaterm/releases/tag/v0.12.1 github.com: https://github.com/Chaterm/Chaterm/blob/v0.12.0/src/main/index.ts#L3442-L3455 vulncheck.com: https://www.vulncheck.com/advisories/chaterm-before-0.12.1-login-csrf-via-chaterm-oauth-callback

Credits

Siyang Wu