CVE-2026-103397

Source
https://cve.org/CVERecord?id=CVE-2026-103397
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103397.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103397
Published
2026-09-30T14:48:57Z
Modified
2026-10-04T02:30:55Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenSave before 2.4.0-beta.1 Authentication Bypass via Spoofed Relay Sender
Details

OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-290"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103397.json"
}
References

Affected packages

Git / github.com/liquid-co/opensave

Affected ranges

Type
GIT
Repo
https://github.com/liquid-co/opensave
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.4.0-beta.1"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.3.1-beta.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103397.json"