Executive brief
TIM Flow is a web application used to manage team workflows and collaboration. A CRLF injection vulnerability in versions before 26.0.6 allows attackers to inject malicious HTTP headers and JavaScript code into the browser of authenticated users by crafting specially crafted URLs. This can lead to session hijacking and unauthorized account access.
Technical details
The vulnerability is a CRLF (Carriage Return Line Feed) injection flaw in the rt URL parameter, which is reflected unsanitized into Set-Cookie response headers. The attack vector is network-based and requires user interaction (an authenticated user must follow a malicious link). By injecting CRLF sequences, an attacker can break out of the HTTP header context and inject arbitrary headers or response body content, including malicious JavaScript. When executed in the user's browser, this enables session token theft and credential modification. The vulnerability is fixed in version 26.0.6 and later.
Affected products
- TIM Flow before 26.0.6
Timeline
- 2026-08-24: disclosed