Description
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the selected view to Flask-WTF's process-global exemption set. The is_token_authenticated() function in src/utils/token_auth.py calls extract_token_from_request() and treats any present token, including request.args.get('token'), as authenticated without hashing the token, querying the database, or checking validity. A network-reachable attacker can therefore send a false token to disable CSRF protection for the targeted view for the worker lifetime. Because the exemption applies to the view function across HTTP methods, a cross-origin GET to /account with a query token can poison CSRF state for a later state-changing POST without triggering CORS preflight. This browser sequence requires attacker-controlled content on a sibling subdomain under the documented cookie conditions. The bypass can modify profile data, custom prompts, transcription settings, preferences, and administrative status through routes such as admin_toggle_admin. The change_password route also skips current-password verification when current_user.password is empty, allowing the chain to set a local password on an SSO-only account and bypass SSO. This issue is fixed in version 0.8.21-alpha.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site request forgery bypass that can lead to unauthorized data modification and privilege escalation
Action: Immediate Patch
AI Analysis

Impact

Speakr, a self‑hosted audio transcription service, contains a flaw in its token authentication and CSRF exemption mechanism. The application treats any supplied token, including those received in URL query parameters, as valid without verification. An attacker can issue a crafted request that calls the csrf_exempt_for_api_tokens hook with a forged token, causing the framework to permanently exempt the targeted view from CSRF checks for all users. This allows a subsequent state‑changing request—such as a POST to /account—to be performed without the original CSRF token, effectively turning a CSRF guard into a no‑op. Because the exemption applies globally to the view, an attacker can alter profile data, transcription settings, and even grant themselves administrative rights through routes like admin_toggle_admin or change_password. The vulnerability is divided into two weaknesses: improper authentication of API tokens and CSRF token bypass.

Affected Systems

Speakr 0.8.x versions older than 0.8.21‑alpha, distributed by murtaza‑nasir, are impacted. All builds that use the buggy src/app.py and src/utils/token_auth.py modules prior to the patch are vulnerable. Users running custom forks that have not addressed the issue remain at risk.

Risk and Exploitability

The flaw has a CVSS score of 7.1, indicating high severity. The EPSS score, less than 1 %, suggests low expected exploitation probability in the short term, and the vulnerability is not listed in the CISA KEV catalog. However, the attack path requires a network‑reachable attacker and the ability to send a query parameter with a token that the application will accept. The attacker must also control a sibling subdomain to satisfy documented cookie conditions. Once the CSRF exemption is installed, the attacker can execute authorized requests without client‑side confirmation, permitting unauthorized modifications of user data and privileges.

Generated by OpenCVE AI on September 19, 2026 at 00:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Speakr to version 0.8.21‑alpha or later to receive the fixed token authentication and CSRF handling logic.
  • If an upgrade is not immediately possible, modify the application to reject tokens passed via URL query parameters or enforce server‑side validation against the database before granting authentication.
  • Disable or restrict the csrf_exempt_for_api_tokens hook for sensitive views, ensuring that only authenticated users with verified tokens can access those endpoints.
  • Review site‑wide CSRF protection settings and enforce SameSite cookie attributes to reduce the risk of cross‑origin request exploitation.

Generated by OpenCVE AI on September 19, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Murtaza-nasir
Murtaza-nasir speakr
Vendors & Products Murtaza-nasir
Murtaza-nasir speakr

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the selected view to Flask-WTF's process-global exemption set. The is_token_authenticated() function in src/utils/token_auth.py calls extract_token_from_request() and treats any present token, including request.args.get('token'), as authenticated without hashing the token, querying the database, or checking validity. A network-reachable attacker can therefore send a false token to disable CSRF protection for the targeted view for the worker lifetime. Because the exemption applies to the view function across HTTP methods, a cross-origin GET to /account with a query token can poison CSRF state for a later state-changing POST without triggering CORS preflight. This browser sequence requires attacker-controlled content on a sibling subdomain under the documented cookie conditions. The bypass can modify profile data, custom prompts, transcription settings, preferences, and administrative status through routes such as admin_toggle_admin. The change_password route also skips current-password verification when current_user.password is empty, allowing the chain to set a local password on an SSO-only account and bypass SSO. This issue is fixed in version 0.8.21-alpha.
Title Speakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_for_api_tokens hook
Weaknesses CWE-287
CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}


Subscriptions

Murtaza-nasir Speakr
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T13:31:09.004Z

Reserved: 2026-06-15T18:01:15.513Z

Link: CVE-2026-54510

cve-icon Vulnrichment

Updated: 2026-09-18T13:31:04.117Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:16.237

Modified: 2026-09-18T14:17:18.303

Link: CVE-2026-54510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:15:13Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-352

    Cross-Site Request Forgery (CSRF)