Executive brief
CrossWatch is a synchronization engine used to manage media library profiles and activity. Prior to version 0.9.21, an unauthenticated attacker can access the /api/app-auth/status endpoint to discover all active user sessions, including their IP addresses, device information (User-Agent), and session timestamps. This leaks operational security details about who is logged in and from where, enabling reconnaissance and geolocation of users without requiring any credentials.
Technical details
The vulnerability is an information disclosure (CWE-200) in the GET /api/app-auth/status endpoint. The /api/app-auth/* route is unconditionally excluded from the authentication middleware, and the _public_session_state() function returns active session metadata without verifying the caller is authenticated. The function only deduplicates the current session when a valid token is present; unauthenticated callers have token=None, causing the guard to never fire and exposing all other_sessions. Attack vector is network-based with no authentication required, no user interaction, and low complexity. An attacker gains low-confidentiality impact by learning session IP addresses, User-Agent strings, internal session IDs, and timestamps. The leaked session IDs are non-secret internal identifiers (not auth cookies) and do not enable session hijacking. Version 0.9.21 fixes the issue by requiring authentication before returning other_sessions data.
Affected products
- cenodude CrossWatch <0.9.21
Timeline
- 2026-05-30: disclosed
- 2026-05-30: patched: Version 0.9.21 released