Junglewise Threat Intelligence

CVE-2026-38978: Transmission clickjacking in WebUI and RPC responses

CVE-2026-38978 · Severity: info · CVSS 0 · Published 2026-06-02

Executive brief

Transmission, a popular BitTorrent client, was found to be vulnerable to clickjacking in its web-based management interface. This flaw could allow a malicious website to trick a logged-in user into performing unintended actions, such as deleting downloads or changing security settings, by overlaying the Transmission interface with invisible elements. Users are advised to update to version 4.1.2 or later to resolve this issue.

Technical details

Transmission versions up to and including 4.1.1 lack proper anti-clickjacking protections in the browser-facing WebUI and RPC response paths. Specifically, the application failed to set 'X-Frame-Options' and 'Content-Security-Policy: frame-ancestors' headers, allowing the interface to be embedded in unauthorized iframes. An attacker could exploit this by hosting a malicious site that frames the Transmission WebUI, potentially leading to UI redressing attacks where users are tricked into interacting with the application's RPC or management functions. The issue was addressed in version 4.1.2 by adding 'X-Frame-Options: SAMEORIGIN' and 'Content-Security-Policy: frame-ancestors 'self'' to HTTP responses.

Affected products

  • Transmission Transmission through 4.1.1

Timeline

  • 2026-03-30: other: Fix proposed in pull request 8747
  • 2026-03-31: patched: Fix merged into main branch and targeted for 4.1.2 milestone
  • 2026-06-02: disclosed: CVE-2026-38978 published

References