qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials: true, effectively allowing any external webpage to make authenticated requests on behalf of a logged-in user. An attacker can exploit this by tricking a victim into loading a malicious webpage, which silently interacts with the application using the victim's session and potentially exfiltrating sensitive data such as API keys and account credentials, or even achieving full system compromise through the built-in External Programs manager. Exploitation requires that the victim access the application via a non-localhost hostname and load an attacker-controlled webpage, making highly targeted social-engineering attacks the most likely real-world scenario. This issue was not fixed at the time of publication.
The Qui application server incorrectly configures the CORS policy — it reflects any value of the Origin header sent by the browser while also allowing session cookies to be included (Access-Control-Allow-Credentials: true). An attacker creates a malicious website to which they lure the victim using social engineering methods. After the page loads, the victim's browser automatically sends authenticated requests to the Qui application within the context of the user's active session. This way, the attacker can silently exfiltrate sensitive data or issue commands through the built-in External Programs manager.
An attacker can gain access to API keys, credentials, and other sensitive information managed by the application, and through the External Programs manager mechanism can achieve full control over the operating system on which the application runs.
At the time of vulnerability publication, no patch was available. Monitor the vendor's repository (https://github.com/autobrr/qui) for patch releases. As a temporary workaround, it is recommended to expose the Qui application only on localhost or restrict access to it using a firewall or VPN, which prevents the conditions necessary for exploitation.
Getqui Qui in versions 1.14.1 and earlier. A successful attack requires the victim to access the application through an address other than localhost and to visit a page controlled by the attacker.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGetqui Qui
APPGetqui< 1.15.0