Junglewise Threat Intelligence

CVE-2026-39915: TIM Flow CRLF injection in rt URL parameter

CVE-2026-39915 · Severity: high · CVSS 8.1 · Published 2026-08-24

Executive brief

TIM Flow is a web application used to manage team workflows and collaboration. A CRLF injection vulnerability in versions before 26.0.6 allows attackers to inject malicious HTTP headers and JavaScript code into the browser of authenticated users by crafting specially crafted URLs. This can lead to session hijacking and unauthorized account access.

Technical details

The vulnerability is a CRLF (Carriage Return Line Feed) injection flaw in the rt URL parameter, which is reflected unsanitized into Set-Cookie response headers. The attack vector is network-based and requires user interaction (an authenticated user must follow a malicious link). By injecting CRLF sequences, an attacker can break out of the HTTP header context and inject arbitrary headers or response body content, including malicious JavaScript. When executed in the user's browser, this enables session token theft and credential modification. The vulnerability is fixed in version 26.0.6 and later.

Affected products

  • TIM Flow before 26.0.6

Timeline

  • 2026-08-24: disclosed

References