Leantime vulnerability

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.

Published 6 Jul 2026Updated 17 Sep 20264 sources
CVSS 8.6

Source timeline

CVE record published by NVDView source ↗