GHSA-p748-5grc-mcf5
User-authored pages served through web requests run on Huginn's origin
01Record
| Identifier | GHSA-p748-5grc-mcf5 |
|---|---|
| Project | Huginn |
| Component | web request route (LiquidOutputAgent, DataOutputAgent) |
| CWE | CWE-79 |
| CVSS | 7.3 |
| Disclosed | 2026-09-08 |
| Endor reference | ENDOR-VUL-2026-27083 |
02Detail
Description: Agents such as LiquidOutputAgent and DataOutputAgent serve content authored by their owner, including HTML and scripts, from Huginn's own origin through the unauthenticated web request route. Affects versions up to 2026.08.27; fixed in 2026.09.08.
Impact: Cross-Site Scripting. A page built by one user and opened by another user of the same instance runs with the viewer's session and can act on Huginn as the viewer, including creating administrators when the viewer is one. Event data interpolated into a LiquidOutputAgent template without the escape filter likewise turns any webhook payload into script on the same origin.
Discovered by Peyton Kennedy (p80n), skeletonsec.