Executive brief
wger is an open-source fitness and workout management platform. A security flaw allows any registered user to view the private workout history, personal session notes, and training statistics of other users. This could lead to the exposure of sensitive personal health data, such as exercise performance, weights used, and private progress notes, to unauthorized individuals.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the RoutineViewSet of wger's REST API. The RoutinePermission.has_object_permission check incorrectly grants read access to any authenticated user if a routine is marked as a template (is_template=True), regardless of who owns the routine. While the /logs/ and /stats/ endpoints are intended to return the requesting user's data, the implementation calls logs_display() and calculate_log_statistics() on the routine object itself, which returns the owner's data instead. An attacker can enumerate public template IDs and retrieve the owner's private session notes, exercise history, and performance metrics. This issue is fixed in version 2.6.
Affected products
- wger-project wger < 2.6
Timeline
- 2026-05-14: advisory: GitHub Security Advisory published
- 2026-07-16: disclosed: NVD publication date