PT-2026-5720 · Unknown+3 · Continuwuity+3
Jadedblueeyes
·
Publicado
2026-02-02
·
Atualizado
2026-02-03
·
CVE-2026-24471
CVSS v4.0
9.3
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H |
Name of the Vulnerable Software and Affected Versions
Continuwuity versions prior to 0.5.1
Conduit versions prior to 0.10.11
Grapevine versions prior to 0aae932b
Tuwunel versions prior to 1.4.9
Description
A flaw exists that allows a malicious remote server to cause a local server to sign an arbitrary event upon user interaction. This occurs when a user account leaves a room, joins a room, or knocks on a room, potentially prompting the victim server to request assistance from a remote server. If the victim requests assistance from an attacker-controlled server, the attacker can provide an arbitrary event, which the victim server will then sign and return. The
/leave endpoint is vulnerable to any event with a supported room version, requiring the origin and origin server ts to be set by the victim. The /join endpoint requires an additional victim-set content field in the format of a join membership. The /knock endpoint requires an additional victim-set content field in the format of a knock membership and a room version not between 1 and 6. This issue was exploited against the continuwuity.org homeserver.Recommendations
Update Continuwuity to version 0.5.1 or later.
Update Conduit to version 0.10.11 or later.
Update Grapevine to version 0aae932b or later.
Update Tuwunel to version 1.4.9 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Conduit
Continuwuity
Grapevine
Tuwunel