Executive brief
Leantime, a project management system, contains a security flaw in how it handles OpenID Connect (OIDC) logins. An attacker can trick a user into clicking a malicious link that forces the user to log into the attacker's account instead of their own. This allows the attacker to potentially capture information about the user's activities or perform actions on their behalf within the platform.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Leantime's OIDC authentication flow due to a stubbed 'verifyState()' method in 'app/Domain/Oidc/Services/Oidc.php'. The method unconditionally returns true, failing to validate the 'state' parameter against the user's session. An attacker can exploit this by crafting a malicious OIDC callback URL containing an attacker-controlled authorization code. If a victim visits this URL, the application completes the token exchange using the attacker's credentials, effectively logging the victim into the attacker's account (session fixation). The vulnerability is present in versions up to 3.4.4 and was addressed in commit 9630eb7.
Affected products
- Leantime Leantime <= 3.4.4
Timeline
- 2026-05-22: disclosed: Initial report to vendor security email
- 2026-06-17: other: Public GitHub issue opened
- 2026-07-06: advisory: NVD publication date