PatchSiren

chaterm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM chaterm CVE published 2026-10-05

CVE-2026-105292

CVE-2026-105292 is a medium-severity login cross-site request forgery vulnerability in Chaterm before version 0.12.1. The vulnerability allows remote attackers to inject login state by sending crafted chaterm:// callbacks without OAuth state validation, potentially leading to unauthorized access and data exposure. Defenders should assess exposure and apply patches or mitigations as available. Chaterm vers [truncated]