Description
wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.
Published: 2026-10-07
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Session Hijacking via CSRF Bypass
Action: Upgrade immediately
AI Analysis

Impact

The flaw resides in the trainer_login view of the wger application, where a GET request triggers a login without a CSRF check. By sending an forged GET request that the client’s browser automatically executes, an attacker can force the target trainer’s session to be rebound to an arbitrary user account. This results in the attacker assuming the identity of that account, enabling full access to its data and functions.

Affected Systems

wger, a free and open-source fitness manager provided by wger‑project, is affected in all releases prior to 2.6. Users running any version before the 2.6 release are vulnerable to this CSRF‑based session rebinding.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4, indicating moderate severity. EPSS data is not available, and the issue is not listed in CISA's KEV catalog, suggesting that widespread exploitation has not yet been observed. In practice, exploitation requires the trainer to visit a malicious page that contains a simple image tag pointing to the vulnerable endpoint, and the trainer must already have an authenticated session. Once satisfied, the attacker can rebind that session to any account, effectively hijacking the trainer’s identity. The attack vector is client‑side, relying on a CSRF bypass of GET requests.

Generated by OpenCVE AI on October 7, 2026 at 15:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade wger to version 2.6 or newer, which removes GET support from trainer_login and enforces proper CSRF protection.
  • If an immediate upgrade is not possible, reconfigure the application to reject GET requests on trainer_login, allowing only POST methods.
  • Apply a middleware or web‑application firewall rule that blocks or logs unexpected GET requests to the trainer_login endpoint to detect potential abuse.

Generated by OpenCVE AI on October 7, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xf64-4pmc-h8qf wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
History

Wed, 07 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Wger-project
Wger-project wger
Vendors & Products Wger-project
Wger-project wger

Wed, 07 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.
Title wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Wger-project Wger
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T17:04:45.845Z

Reserved: 2026-05-08T20:44:38.965Z

Link: CVE-2026-45161

cve-icon Vulnrichment

Updated: 2026-10-07T15:27:06.390Z

cve-icon NVD

Status : Deferred

Published: 2026-10-07T14:17:10.087

Modified: 2026-10-07T17:16:55.703

Link: CVE-2026-45161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T15:45:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)