TROYANOSYVIRUS
Back to CVEs

CVE-2026-40471

CRITICAL
9.6

Description

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).

CVE Details

CVSS v3.1 Score9.6
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published4/23/2026
Last Modified4/24/2026
Sourcenvd
Honeypot Sightings0

Weaknesses (CWE)

CWE-352

References

https://osv.dev/vulnerability/HSEC-2026-0002(74b3a70d-cca6-4d34-9789-e83b222ae3be)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.