Cross-site request forgery in HFS - CVE-2026-61502
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform unauthorized state-changing API operations.
The vulnerability exists due to improper cross-site request forgery protection in GET API handling when a browser sends a crafted GET request to a state-changing API. A remote attacker can trick a user into visiting a crafted URL to perform unauthorized state-changing API operations.