Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Tawk.to - Live chat application - Critical - Cross Site Request Forgery - SA-CONTRIB-2026-184

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Tawk.to - Live chat application - Critical - Cross Site Request Forgery - SA-CONTRIB-2026-184


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Tawk.to - Live chat application - Critical - Cross Site Request Forgery - SA-CONTRIB-2026-184
  • Date: Wed, 23 Sep 2026 17:14:49 +0000
  • Arc-authentication-results: i=2; smtp4.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=SQUiHLHm; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=cf1nfji5; arc=none smtp.remote-ip=54.240.27.34
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org D6EA050C3E
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org D4BB680C38
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790187374; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=KJZp9fs8RcyZJ+kMjGc36vxCxfVN26SQzDIpfs8LnYQ=; b=ih47e1V/rFL0QvsovoCJeO+JTiBGvDxDcNkiQona1UIGypLFnN1h9TaFk91M09VqzyLX ex08GlGHX2jWSJhWgnmUy0faFqj1a9ua/0XF7Y2axUVqU7nfxh7woTlH6tWXl2NFUo9mO Xyxtfj6eEU5kzaJoReRsCnHcn/M5hJkMvJQlTJpcB4yx6x5b+9TA1EkbDjOYyql2/yqzK Gnpk92zyhEnj7GEdzyN8qOGuw7MB2PVTkAKhznZf+BIyVFomXM7sCKrNl9Ep21sMYk3E/ WSxqrq3yzsHuutQmFJUXi3gfglmtJkSWFnFY4j3FPs/SqSFBkDE6Dj5PDs+I1unMY3g==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790183691; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=JXRjOXnKycBBpMkvwKv+wrsibLpGyVkA0WPWlMn9TV4=; b=QJLvDtfaeSaNpNDoLvrubfV3GmcyM47jKO50ctmV9EMXPIHXHaUVGoYunJz1ufEJuMkh 52e/KqRUx7jxiWISIGn2Y7OlAE0bWV+IrwjaRZVFXBK330lEhlX72isJx8oJkWXSMr8DM Qj6MZygUkRiuRUcDNajbQFz7iazYlNkm2c7h5DqoNDFur9ub9yeEU6iY2IiCN2NPgpA+N LI+w20zoHZ8GkWRyVD+idc7CxBkBQXA8/iMUhqm8HyRlbP823o5wSl03Qt7E7c0ON1ccd o2RcRUmELwX1fE9H+j31lJ3niovUgsnErJs37+LzSupg2QDaKU8jOoG7Btr7dwfAZZQ==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790187374; b=jjU+eqCEc3REBt93baALD4M9ENt4BmhmON8DT5sfv2EXv2/zmMQR+P/HA38qkPErbglB SlIruG7RxBf08h9vJb1cyPc5IwgbPgLhaTm0tzEDwKbKwTOw/Gh4AnkzKqTt3L1yyoCdq wtP+gIZpX2Yo+wV7tquZQfklnBTQaCEZRLQ6CYnX6D+7ynYhIrmBbz7vfZR1egCaiNM0t iVEWD7Qt++cm8gNH9YdqUiLD109RahLDh/wBF1m4pGLvJRv2p34VFkKYPUUGShEf6NlzN +edBatWMaAh/L/jKhJnXCwVZ9XMdcdXIRhojkA7+lEbRC0VPdf0hRX3QueGgX0h/5HA==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790183691; b=iLBY5Ultz5m1ZLnODbulBlHPjd3EFQPHiqx8Q6vGsft0xnBHr9JP82DMhtqv3/TBMnNz xqaW0bXDBHn8bVH38GU8gA4bZJ7mIMxTiu36UuTE6gYh+UlgsBExgHGtd/cTvF8MPiCzn XctLeIj5A3EGMNCXEMvdwFumDbahkXjd623jQOVzitEUXShrGVT2nudIT06XIRQWdWLv5 2TwwtGdLcOM6s1V4A6179guBkv48tKYnQqPMFFPW4bHBjdOR0/M0h3Hsfz3v5LVcqUh2I 1Sx6b+fZJEv0VYvk6vp+nW+33LJYr/2Ym61D46miolzveObBL744l4Bx3pkRyt23gFA==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/OCMY3WQAACTXJZP7ENM4SMNJQC7YQVCR/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=JdQEKyhf; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=SQUiHLHm; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=cf1nfji5; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-184

Project: Tawk.to - Live chat application [1]
Project machine name: tawk_to
Date: 2026-September-23
Security risk: *Critical* 16 ∕ 25
AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Cross Site Request Forgery

Affected versions: <3.0.4
CVE IDs: CVE-2026-96388
Description: 
This module provides integration of the tawk.to live chat for Drupal sites.

The module does not sufficiently validate certain requests. This may allow an
attacker to trick an authenticated user into performing unintended actions
through a Cross-Site Request Forgery (CSRF) vulnerability.

Solution: 
Install the latest version:

* Upgrade to tawk.to 3.0.4 [3].

After updating, clear the Drupal cache.

Reported By: 
* Tin Nguyen Huu (s4m0y3d) [4]

Fixed By: 
* Andriy Khomych (andriy khomych) [5]
* Tin Nguyen Huu (s4m0y3d) [6]

Coordinated By: 
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Bram Driesen (bramdriesen) [8] of the Drupal Security Team
* Damien McKenna (damienmckenna) [9] of the Drupal Security Team
* Greg Knaddison (greggles) [10] of the Drupal Security Team
* Juraj Nemec (poker10) [11] of the Drupal Security Team
* Jess (xjm) [12] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [13]

[1] https://www.drupal.org/project/tawk_to
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/tawk_to/releases/3.0.4
[4] https://www.drupal.org/u/s4m0y3d
[5] https://www.drupal.org/u/andriy-khomych
[6] https://www.drupal.org/u/s4m0y3d
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/bramdriesen
[9] https://www.drupal.org/u/damienmckenna
[10] https://www.drupal.org/u/greggles
[11] https://www.drupal.org/u/poker10
[12] https://www.drupal.org/u/xjm
[13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3623898

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Tawk.to - Live chat application - Critical - Cross Site Request Forgery - SA-CONTRIB-2026-184, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang