Junglewise Threat Intelligence

CVE-2026-9323: urwid insecure PRNG and session hijacking in web display backend

CVE-2026-9323 · Severity: high · CVSS 8.1 · Published 2026-07-18

Executive brief

Urwid is a Python library used to create terminal-based user interfaces. Its web display component uses weak, predictable session identifiers that can be guessed by an attacker or found in temporary system folders. If exploited, an attacker can take over a user's session, view their screen, and execute commands with the user's permissions.

Technical details

The urwid web display backend (urwid/display/web.py) generates session identifiers (urwid_id) using Python's Mersenne Twister PRNG, which is not cryptographically secure. An attacker observing approximately 334 session IDs (e.g., via the X-Urwid-ID header) can reconstruct the PRNG state to predict future IDs. Additionally, these IDs are used as filenames for FIFOs in the world-readable /tmp directory, allowing local users to enumerate active tokens. Possession of a valid session ID allows an attacker to read the terminal screen via the polling endpoint or inject keystrokes, potentially leading to OS-level code execution if the session is running a shell. The issue has been addressed in recent commits by switching to the 'secrets' module and UUID4 for identifier generation.

Affected products

  • urwid urwid <= 24acd12 (git)

Timeline

  • 2026-04-27: disclosed: Initial private disclosure by researcher Katriel Moses
  • 2026-04-28: patched: Fix merged into master branch
  • 2026-07-18: advisory: NVD and VulnCheck advisories published

References