PT-2026-95103 · Speaker · Speaker

·

CVE-2026-54510

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Speakr versions prior to 0.8.21-alpha
Description An issue exists where the csrf exempt for api tokens() before request hook in src/app.py calls csrf.exempt(view func), which permanently adds the selected view to the process-global exemption set of Flask-WTF. Additionally, the is token authenticated() function in src/utils/token auth.py uses extract token from request() to treat any provided token, such as the token variable in request.args.get('token'), as authenticated without performing hashing, database queries, or validity checks. A network-reachable attacker can provide a false token to disable Cross-Site Request Forgery (CSRF) protection for a targeted view for the duration of the worker lifetime. A cross-origin GET request to the '/account' endpoint with a query token can poison the CSRF state for subsequent state-changing POST requests. This allows the modification of profile data, custom prompts, transcription settings, preferences, and administrative status via routes like admin toggle admin. Furthermore, the change password route may skip current-password verification if current user.password is empty, potentially allowing an attacker to set a local password on an SSO-only account and bypass Single Sign-On (SSO) authentication.
Recommendations Update to version 0.8.21-alpha.

Exploit

Fix

CSRF

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54510
GHSA-X4Q4-3WW4-H329

Affected Products

Speaker