PT-2026-24782 · Taskosaur+1 · Taskosaur

G3Xar

·

Publicado

2026-03-11

·

Atualizado

2026-03-12

·

CVE-2026-31874

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Taskosaur version 1.0.0
Description Taskosaur is an open source project management platform with conversational AI for task execution within the application. The application does not properly validate or restrict the role parameter during the user registration process. An attacker can manually modify the request payload to assign themselves elevated privileges. The backend does not enforce role assignment restrictions or ignore client-supplied role parameters, allowing the server to accept the manipulated value and create an account with SUPER ADMIN privileges. This enables any unauthenticated attacker to register a fully privileged administrative account. The vulnerable parameter is role.
Recommendations Versions prior to 1.0.0 are not affected. For version 1.0.0, properly validate and restrict the role parameter during the user registration process to prevent unauthorized privilege escalation.

Exploit

Correção

IDOR

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31874
GHSA-R6GJ-4663-P5MR

Produtos afetados

Taskosaur