๐Ÿ” CVE Alert

CVE-2026-27632

LOW 2.6

Talishar Vulnerable to Cross-Site Request Forgery (CSRF)

CVSS Score
2.6
EPSS Score
0.0%
EPSS Percentile
0th

Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar application lacks Cross-Site Request Forgery (CSRF) protections on critical state-changing endpoints, specifically within `SubmitChat.php` and other game interaction handlers. By failing to require unique, unpredictable session tokens, the application allows third-party malicious websites to forge requests on behalf of authenticated users, leading to unauthorized actions within active game sessions. The attacker would need to know both the proper gameName and playerID for the player. The player would also need to be browsing and interact with the infected website while playing a game. The vulnerability is fixed in commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48.

CWE CWE-352
Vendor talishar
Product talishar
Published Feb 25, 2026
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for talishar talishar

Be the first to know when new low vulnerabilities affecting talishar talishar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Talishar / Talishar
< 6be3871a14c192d1fb8146cdbc76f29f27c1cf48

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Talishar/Talishar/security/advisories/GHSA-73mm-323r-cm3g