CVE-2026-105292

Summary

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the victim into the attacker's account so default data sync uploads saved hosts, passwords, and private keys.

Affected Software

VendorProductVersion RangeStatus
chatermChaterm0.2.0 < 0.12.1affected

Weaknesses

  • CWE-352: Cross-Site Request Forgery (CSRF)

References