Executive brief
web.py is a lightweight Python web framework that manages user sessions through a session component. A session fixation vulnerability allows an attacker to hijack an authenticated session by planting a known session identifier in a user's browser before login, then reusing that identifier after the victim authenticates. The vulnerability requires the application to store authentication state in web.py's session component and not regenerate session IDs after login.
Technical details
The Session._load() method reads the session_id directly from the request cookie without rotation, and _save() writes session data back under the same identifier. The vulnerability (CWE-384) stems from the absence of session identifier regeneration following authentication state changes. An attacker must plant a valid session identifier into the victim's browser before authentication, requiring control over a cookie-writing channel or man-in-the-middle position; the downstream application must also store authentication state in this session component without rotating the identifier post-login.
Affected products
- webpy web.py 0.76
Timeline
- 2026-09-22: disclosed
- 2026-08-04: other: reported to project