Impact
Speakr, a self‑hosted audio transcription service, contains a flaw in its token authentication and CSRF exemption mechanism. The application treats any supplied token, including those received in URL query parameters, as valid without verification. An attacker can issue a crafted request that calls the csrf_exempt_for_api_tokens hook with a forged token, causing the framework to permanently exempt the targeted view from CSRF checks for all users. This allows a subsequent state‑changing request—such as a POST to /account—to be performed without the original CSRF token, effectively turning a CSRF guard into a no‑op. Because the exemption applies globally to the view, an attacker can alter profile data, transcription settings, and even grant themselves administrative rights through routes like admin_toggle_admin or change_password. The vulnerability is divided into two weaknesses: improper authentication of API tokens and CSRF token bypass.
Affected Systems
Speakr 0.8.x versions older than 0.8.21‑alpha, distributed by murtaza‑nasir, are impacted. All builds that use the buggy src/app.py and src/utils/token_auth.py modules prior to the patch are vulnerable. Users running custom forks that have not addressed the issue remain at risk.
Risk and Exploitability
The flaw has a CVSS score of 7.1, indicating high severity. The EPSS score, less than 1 %, suggests low expected exploitation probability in the short term, and the vulnerability is not listed in the CISA KEV catalog. However, the attack path requires a network‑reachable attacker and the ability to send a query parameter with a token that the application will accept. The attacker must also control a sibling subdomain to satisfy documented cookie conditions. Once the CSRF exemption is installed, the attacker can execute authorized requests without client‑side confirmation, permitting unauthorized modifications of user data and privileges.
OpenCVE Enrichment