← All research

GHSA-p748-5grc-mcf5

User-authored pages served through web requests run on Huginn's origin

01Record

IdentifierGHSA-p748-5grc-mcf5
ProjectHuginn
Componentweb request route (LiquidOutputAgent, DataOutputAgent)
CWECWE-79
CVSS7.3
Disclosed2026-09-08
Endor referenceENDOR-VUL-2026-27083

02Detail

Description: Agents such as LiquidOutputAgent and DataOutputAgent serve content authored by their owner, including HTML and scripts, from Huginn's own origin through the unauthenticated web request route. Affects versions up to 2026.08.27; fixed in 2026.09.08.

Impact: Cross-Site Scripting. A page built by one user and opened by another user of the same instance runs with the viewer's session and can act on Huginn as the viewer, including creating administrators when the viewer is one. Event data interpolated into a LiquidOutputAgent template without the escape filter likewise turns any webhook payload into script on the same origin.

Discovered by Peyton Kennedy (p80n), skeletonsec.