A server-side vulnerability affecting github.com/komari-monitor/komari versions < 0.0.0-20260609084633-98122fa4d110 with a CVSS score of 9.8 exists in the affected version range, allowing cross-site request forgery (CSRF) attacks on admin endpoints due to the session_token cookie being set without the SameSite or Secure attributes. This issue affects high-impact operations such as executing arbitrary shell commands, disabling administrator two-factor authentication, modifying system configuration, uploading malicious backups, deleting all monitoring records, and removing managed clients. The vulnerability is confirmed to exist but exploitation via cross-site requests is mitigated in modern browsers by the default SameSite=Lax behavior. Legacy browsers and same-origin contexts are vulnerable due to cookies without an explicit SameSite attribute not being included in cross-site POST requests. This allows attackers to bypass CORS preflight and execute malicious actions on affected systems, resulting in significant business impact.
We recommend you to update komari to version 0.0.0-20260609084633-98122fa4d110.[/subscribe_to_unlock_form]
A server-side vulnerability affecting github.com/komari-monitor/komari versions < 0.0.0-20260609084633-98122fa4d110 with a CVSS score of 9.8 exists in the affected version range, allowing cross-site request forgery (CSRF) attacks on admin endpoints due to the session_token cookie being set without the SameSite or Secure attributes. This issue affects high-impact operations such as executing arbitrary shell commands, disabling administrator two-factor authentication, modifying system configuration, uploading malicious backups, deleting all monitoring records, and removing managed clients. The vulnerability is confirmed to exist but exploitation via cross-site requests is mitigated in modern browsers by the default SameSite=Lax behavior. Legacy browsers and same-origin contexts are vulnerable due to cookies without an explicit SameSite attribute not being included in cross-site POST requests. This allows attackers to bypass CORS preflight and execute malicious actions on affected systems, resulting in significant business impact.
We recommend you to update komari to version 0.0.0-20260609084633-98122fa4d110.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]