PT-2026-90950 · Cheshire Cat Ai+1 · Cheshire Cat Ai+1
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
cheshire-cat-ai versions prior to 1.9.3
Description
An issue exists where the manipulation of the
user id argument in the authorize http key() function within the core/cat/factory/custom auth handler.py file leads to missing authentication. This allows a remote attacker to impersonate any user, including the administrator, by providing a specific client header. This occurs in default installations where no API key is configured.Recommendations
Set the
CCAT API KEY environment variable to enable authentication.
Remove the server from the open internet to restrict access.
As a temporary workaround, restrict access to the authorize http key() function until a patch is available.Exploit
Fix
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cheshire Cat Ai
Core