PT-2026-105854 · Pypi · Mesop
Publicado
2026-10-01
·
Atualizado
2026-10-01
CVSS v4.0
5.3
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N |
Summary
The
/ csp endpoint accepts unauthenticated JSON reports and logs user-controlled values directly to stdout using print() without escaping control characters.A remote attacker can include ANSI/VT100 escape sequences in fields such as
blocked-uri or document-uri. When the logs are viewed in an ANSI-capable terminal, these sequences can manipulate the displayed output (e.g., clear the screen, hide text, or inject misleading messages), affecting the integrity of operator-facing logs.Details
The CSP reporting endpoint accepts arbitrary JSON and prints several request fields directly:
mesop/server/static file serving.py
python
@app.route(prefix base url("/ csp "), methods=["POST"])
def csp report():
report = request.get json(force=True)
document uri = report["csp-report"]["document-uri"]
blocked uri = report["csp-report"]["blocked-uri"]
violated directive = report["csp-report"]["violated-directive"]
print(f"... Blocked URL: {blocked uri} ...")Since these values are written to stdout without sanitization, ANSI escape sequences supplied by a remote client are preserved and interpreted by ANSI-compatible terminals.
PoC
Send the following request:
http
POST / csp
Content-Type: application/json
{
"csp-report": {
"document-uri": "https://victim.example",
"blocked-uri": "u001b[2Ju001b[Hu001b[32m*** SECURITY OK - No CSP violations found ***u001b[0m
u001b[8mhttps://evil.example",
"violated-directive": "script-src-elem"
}
}The request is accepted (HTTP 204), and the injected escape sequences are written to stdout unchanged.
When the captured output is rendered in a VT100-compatible terminal (verified using
pyte), the original CSP warning is visually replaced with attacker-controlled content.Expected output
text
Content Security Policy Error
Directive: script-src-elem
Blocked URL: ...
App path: /appRendered output
text
*** SECURITY OK - No CSP violations found ***
https://evil.example
App path: /appImpact
An unauthenticated remote attacker can submit a crafted request to the / csp endpoint containing ANSI/VT100 escape sequences. Because these values are written directly to stdout without sanitization, an attacker can:
- Inject forged log messages that appear to originate from the application.
- Manipulate the terminal display by clearing the screen, moving the cursor, or overwriting previously displayed log output.
- Hide or disguise security-relevant log entries using terminal formatting sequences such as colors, hidden text, or cursor positioning.
- Mislead administrators during monitoring or incident response by displaying attacker-controlled messages (e.g., fake "SECURITY OK" notifications).
- Reduce the integrity and trustworthiness of operator-facing logs, making troubleshooting and security investigations less reliable.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mesop