Executive brief
Pachno, an open-source project management and collaboration platform, contains a security flaw that could allow an attacker to trick a logged-in user into performing unintended actions. By luring a user to a malicious website, an attacker could force the user's browser to change account settings, upload files, or modify project milestones without their consent. This could lead to unauthorized data modification, account takeovers, or disruption of project workflows.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Pachno versions up to and including 1.0.6 due to missing anti-CSRF protections (such as tokens) on critical state-changing endpoints. An attacker can exploit this by crafting malicious HTML pages or scripts that trigger requests to the vulnerable application when visited by an authenticated user. Affected functions include login/logout, user registration, file uploads, milestone editing, and various administrative tasks. Successful exploitation allows an attacker to modify application state, inject comments, or change user roles, provided they can convince a victim with the necessary privileges to visit a malicious URL.
Affected products
- Pachno Pachno <= 1.0.6
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory