CVE-2026-45161
Deferred Deferred - Pending Action

CSRF Bypass in wger Workout Manager

Vulnerability report for CVE-2026-45161, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wger-project wger < 2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Request Forgery (CSRF) vulnerability in the wger fitness application affecting versions prior to 2.6. The trainer_login view improperly accepts GET requests without CSRF protection. An attacker can embed a malicious image tag on a webpage that, when loaded by an authenticated trainer, forces their browser to send a GET request to the trainer_login endpoint. This rebinds the trainer's session to another user account without their consent.

Detection Guidance

To detect this vulnerability, check if your wger instance is running a version prior to 2.6. Review server logs for unusual GET requests to the trainer_login endpoint from authenticated users. Inspect web pages for embedded malicious image tags or scripts that could trigger the vulnerability.

Impact Analysis

An attacker could hijack your session and gain access to your account, potentially allowing them to view or modify your workout data, personal information, or other sensitive details. They might also redirect you to malicious sites for further phishing or credential theft.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized session hijacking. An attacker could forcibly rebind a trainer's session to another account, potentially gaining access to sensitive personal data or fitness information. This unauthorized access may violate data protection requirements under GDPR (e.g., unauthorized processing of personal data) and HIPAA (e.g., improper access to protected health information).

Mitigation Strategies

Upgrade wger to version 2.6 or later immediately. Ensure the trainer_login view only accepts POST requests and moves sensitive parameters like next into the POST body. Verify CSRF protection is enforced for all sensitive endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-45161. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart