Speaker · Speaker · CVE-2026-54510
**Name of the Vulnerable Software and Affected Versions**
Speakr versions prior to 0.8.21-alpha
**Description**
An issue exists where the `csrf exempt for api tokens()` before request hook in `src/app.py` calls `csrf.exempt(view func)`, which permanently adds the selected view to the process-global exemption set of Flask-WTF. Additionally, the `is token authenticated()` function in `src/utils/token auth.py` uses `extract token from request()` to treat any provided token, such as the `token` variable in `request.args.get('token')`, as authenticated without performing hashing, database queries, or validity checks. A network-reachable attacker can provide a false token to disable Cross-Site Request Forgery (CSRF) protection for a targeted view for the duration of the worker lifetime. A cross-origin GET request to the '/account' endpoint with a query token can poison the CSRF state for subsequent state-changing POST requests. This allows the modification of profile data, custom prompts, transcription settings, preferences, and administrative status via routes like `admin toggle admin`. Furthermore, the `change password` route may skip current-password verification if `current user.password` is empty, potentially allowing an attacker to set a local password on an SSO-only account and bypass Single Sign-On (SSO) authentication.
**Recommendations**
Update to version 0.8.21-alpha.