VYPR
Medium severity5.4GHSA Advisory· Published Oct 7, 2026· Updated Oct 7, 2026

CVE-2026-45161

CVE-2026-45161

Description

wger is a free, open-source workout and fitness manager. Prior to version 2.6, the trainer_login view in wger accepts GET requests and executes django_login() without any CSRF protection, because Django's CsrfViewMiddleware only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.