AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-45161.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Summary The `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. ### Details **File**: `wger/core/views/user.py`, approximately lines 161-210 ```python # VULNERABLE - no @require_POST, no request.method == 'POST' guard # CsrfViewMiddleware is bypassed because CSRF enforcement only applies to # unsafe HTTP methods (POST, PUT, PATCH, DELETE) def trainer_login(request, user_pk): ... django_login(request, user, backend='django.contrib.auth.backends.ModelBackend') return HttpResponseRedirect(...) ``` Because the view handles GET, Django's CSRF middleware does not validate any token. An attacker can place `` on any web page. When an authenticated trainer's browser loads that page, it issues the GET request with the session cookie attached (SameSite=Lax does not block same-site top-level navigation

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-xf64-4pmc-h8qf

Open original source · Updated Oct 07, 2026

wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
pipwgerNot supplied

Original records & references

PUBLISHED 2026-10-07T09:45:33-04:00
MODIFIED 2026-10-07T09:45:36-04:00
INGESTED 2026-10-08T12:05:11-04:00