Executive brief
Chaskiq is a customer engagement platform offering live chat, support, and marketing features. A missing authentication vulnerability allows attackers to manipulate Stripe payment subscriptions for any customer without valid credentials, potentially enabling unauthorized billing changes and fraudulent charges.
Technical details
The vulnerability is an authentication bypass in the stripeCreateIntent GraphQL mutation within Chaskiq (through commit 46dfdd1). The mutation lacks authentication and authorization checks, allowing unauthenticated remote attackers to create Stripe payment intents and modify billing for any tenant. The GraphQL endpoint is network-accessible without requiring valid credentials or API tokens. An attacker can invoke the mutation to alter subscription billing, create unauthorized charges, or disrupt service for multiple customers. No patch information is currently available in the advisory.
Affected products
- Chaskiq Chaskiq through commit 46dfdd1
Timeline
- 2026-08-11: disclosed