Leantime vulnerability

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.

Published 6 Jul 2026Updated 17 Sep 20264 sources
CVSS 8.6

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.