PT-2024-22679 · Owncast · Owncast

·

CVE-2024-29026

·

Published

2024-03-20

·

Updated

2025-10-14

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Owncast versions 0.1.2 and prior
Description Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. A lenient CORS policy allows attackers to make a cross origin request, reading privileged information, which can be used to leak the admin password.
Recommendations For versions 0.1.2 and prior, update to a version that includes the fix from commit 9215d9ba0f29d62201d3feea9e77dcd274581624 to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-29026
GHSA-V99W-R56H-G23V
GO-2024-3054

Affected Products

Owncast