Impact
The vulnerability is a cross‑site request forgery that occurs when Chaterm processes callbacks from its OAuth flow without validating a state parameter. A malicious web page can craft a chaterm:// URL that includes arbitrary userInfo, causing the victim’s application to authenticate as the attacker without the victim's consent. This permits an attacker to log in with the victim’s context, after which the application automatically synchronizes saved hosts, passwords, and private keys, exposing sensitive credential material. The weakness is a classic CSRF flaw (CWE‑352) that can compromise both the confidentiality and integrity of the user’s data.
Affected Systems
Affected systems are installations of Chaterm older than version 0.12.1. All releases prior to that, including 0.12.0 and earlier, lack the state validation in the OAuth callback, making them vulnerable. The product name is simply Chaterm, and the affected vendor is Chaterm. No specific sub‑versions beyond the cut‑off are listed, so any deployment below 0.12.1 should be considered at risk.
Risk and Exploitability
The CVSS base score is 6.0, which represents a moderate severity under the CVSSx3 framework. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, indicating no known widespread exploitation. Nonetheless, the attack requires only that a victim load a malicious web page that triggers a chaterm:// callback; no additional privileges or credentials are needed. The absence of state validation makes the exploit straightforward, and the payload is delivered through a standard browser, highlighting a realistic threat scenario for users who routinely open remote pages.
OpenCVE Enrichment