Untriaged
Permalink
CVE-2026-5302
6.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
Permissive Cross-domain Policy with Untrusted Domains in coolercontrold
CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites
References
Affected products
coolercontrold
- <4.0.0
Package maintainers
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>
-
@codifryed Guy Boldon <gb@guyboldon.com>