Threat Advisory

Gin Flaw Allows CSRF Attacks on Admin Endpoints

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A server-side vulnerability affecting github.com/komari-monitor/komari versions < 0.0.0-20260609084633-98122fa4d110 with a CVSS score of 9.8 exists in the affected version range, allowing cross-site request forgery (CSRF) attacks on admin endpoints due to the session_token cookie being set without the SameSite or Secure attributes. This issue affects high-impact operations such as executing arbitrary shell commands, disabling administrator two-factor authentication, modifying system configuration, uploading malicious backups, deleting all monitoring records, and removing managed clients. The vulnerability is confirmed to exist but exploitation via cross-site requests is mitigated in modern browsers by the default SameSite=Lax behavior. Legacy browsers and same-origin contexts are vulnerable due to cookies without an explicit SameSite attribute not being included in cross-site POST requests. This allows attackers to bypass CORS preflight and execute malicious actions on affected systems, resulting in significant business impact.

RECOMMENDATION:

We recommend you to update komari to version 0.0.0-20260609084633-98122fa4d110.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A server-side vulnerability affecting github.com/komari-monitor/komari versions < 0.0.0-20260609084633-98122fa4d110 with a CVSS score of 9.8 exists in the affected version range, allowing cross-site request forgery (CSRF) attacks on admin endpoints due to the session_token cookie being set without the SameSite or Secure attributes. This issue affects high-impact operations such as executing arbitrary shell commands, disabling administrator two-factor authentication, modifying system configuration, uploading malicious backups, deleting all monitoring records, and removing managed clients. The vulnerability is confirmed to exist but exploitation via cross-site requests is mitigated in modern browsers by the default SameSite=Lax behavior. Legacy browsers and same-origin contexts are vulnerable due to cookies without an explicit SameSite attribute not being included in cross-site POST requests. This allows attackers to bypass CORS preflight and execute malicious actions on affected systems, resulting in significant business impact.

RECOMMENDATION:

We recommend you to update komari to version 0.0.0-20260609084633-98122fa4d110.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu