Description
A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-01-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site request forgery
Action: Assess Impact
AI Analysis

Impact

A security vulnerability was detected in birkir prime versions up to 0.4.0.beta.0 that allows attackers to exploit unprotected endpoints and trigger cross‑site request forgery. The flaw, identified as a missing or ineffective CSRF defense, permits remote actors to perform state‑changing actions on behalf of authenticated users, potentially compromising application integrity and user accounts.

Affected Systems

The vulnerability affects birkir prime installations where the software version is 0.4.0.beta.0 or earlier. No further version details are provided, and the issue is not limited to a specific configuration of the product.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk, while the EPSS probability of less than 1% suggests exploitation is unlikely to be widespread at present. The vulnerability can be initiated remotely via the application’s exposed endpoints, and the publicly disclosed exploit could be weaponized against any unpatched deployment. The flaw is currently not listed in CISA’s KEV catalog, reflecting its limited exposure or lack of known exploitation incidents.

Generated by OpenCVE AI on April 18, 2026 at 05:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Determine whether any installed birkir prime instance is running version 0.4.0.beta.0 or earlier, and check the project’s release history for a later version that removes the CSRF flaw.
  • If a patched version exists, update the software to that release; if no fix is available, add a server‑side CSRF token check that validates unique, per‑session tokens before processing state‑changing requests.
  • Restrict the vulnerable endpoints to trusted administrators by applying network segmentation or firewall rules that block public access.
  • Continue monitoring the project's issue tracker and security advisories for an official fix, and be prepared to decommission the affected component if no patch is released within an acceptable timeframe.

Generated by OpenCVE AI on April 18, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
References

Wed, 04 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:birkir:prime:*:*:*:*:*:*:*:*

Tue, 20 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Birkir
Birkir prime
Vendors & Products Birkir
Birkir prime

Mon, 19 Jan 2026 17:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title birkir prime cross-site request forgery
Weaknesses CWE-352
CWE-862
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:47:53.591Z

Reserved: 2026-01-19T07:15:22.297Z

Link: CVE-2026-1169

cve-icon Vulnrichment

Updated: 2026-01-20T15:13:54.408Z

cve-icon NVD

Status : Modified

Published: 2026-01-19T18:16:04.583

Modified: 2026-02-23T09:16:48.770

Link: CVE-2026-1169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T05:15:15Z

Weaknesses