CVE-2026-30924 affects qui, a web interface for qBittorrent instances up to version 1.14.1, due to a permissive Cross-Origin Resource Sharing (CORS) policy that reflects arbitrary origins while also returning credentials. This Critical (CVSS 9.0) vulnerability allows an attacker to trick a logged-in user into loading a malicious webpage, enabling authenticated requests on their behalf. The potential impact is severe, ranging from sensitive data exfiltration and API key compromise to full system compromise via the External Programs manager. Exploitation requires social engineering to lure a victim to an attacker-controlled page while they are accessing the application via a non-localhost hostname. Currently, there is no public exploit code available, nor any indication of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.15.0CPE matchmatch criteria | cpe:2.3:a:getqui:qui:*:*:*:*:*:docker:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.