Junglewise Threat Intelligence

CVE-2026-48518: OWASP MultiJuicer CSRF in team join endpoint

CVE-2026-48518 · Severity: medium · CVSS 4.3 · Published 2026-06-15

Vendors: OWASP.

Executive brief

MultiJuicer, a platform used to manage multiple instances of the Juice Shop security training application, is vulnerable to a login-related security flaw. An attacker can trick a user into visiting a malicious website that automatically logs them into the attacker's team account. This allows the attacker to steal the victim's progress in security challenges or capture sensitive data the victim enters into what they believe is their own private instance.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the MultiJuicer team join endpoint (POST /multi-juicer/api/teams/{team}/join). The endpoint fails to strictly validate the Content-Type header, accepting 'text/plain' requests which do not trigger a CORS preflight check in web browsers. An unauthenticated remote attacker can exploit this by hosting a malicious HTML form that auto-submits to the endpoint, forcing the victim's browser to establish a session under the attacker's team identity. This bypasses SameSite=Strict cookie protections because the attack plants a new session cookie rather than hijacking an existing one. The issue is resolved in version 10.0.1 by requiring the 'application/json' Content-Type for all JSON POST endpoints.

Affected products

  • OWASP Juice Shop Project MultiJuicer 8.0.0 - 10.0.0

Timeline

  • 2026-05-21: disclosed: Issue reported and fix suggested via GitHub issue #525
  • 2026-05-21: patched: Fix committed to repository
  • 2026-06-15: advisory: CVE-2026-48518 published

References