Impact
hackage‑server was found to lack cross‑site request forgery protection. The vulnerability allows an attacker to craft malicious scripts hosted on a foreign domain that trick a victim’s browser into issuing authenticated or unauthenticated requests to the hackage server. This can be used to upload malicious packages, change repository metadata, or create new user accounts, potentially affecting the integrity of the package repository. The weakness is a classic CSRF flaw (CWE‑352).
Affected Systems
The target product is hackage‑server; no specific version range is listed in the advisory, so all installations of hackage‑server are potentially affected until a patch is applied.
Risk and Exploitability
The CVSS score of 9.6 indicates that the flaw is severe. The EPSS score of less than 1 % suggests that exploitation is considered unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote client‑side attack where the user’s browser is tricked into sending requests, which means that any user who accesses a malicious page while authenticated to hackage‑server faces risk. As the vulnerability allows both authenticated and some unauthenticated administrative actions, an attacker could gain administrative capabilities such as uploading packages or creating accounts once credentials are compromised or new accounts are created. The combination of a high severity score and low exploitation probability still warrants prompt mitigation.
OpenCVE Enrichment