Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-30924

31
FAUCET Score

CVE-2026-30924 affects qui, a web interface for qBittorrent instances up to version 1.14.1, due to a permissive Cross-Origin Resource Sharing (CORS) policy that reflects arbitrary origins while also returning credentials. This Critical (CVSS 9.0) vulnerability allows an attacker to trick a logged-in user into loading a malicious webpage, enabling authenticated requests on their behalf. The potential impact is severe, ranging from sensitive data exfiltration and API key compromise to full system compromise via the External Programs manager. Exploitation requires social engineering to lure a victim to an attacker-controlled page while they are accessing the application via a non-localhost hostname. Currently, there is no public exploit code available, nor any indication of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.15.0CPE matchmatch criteria
cpe:2.3:a:getqui:qui:*:*:*:*:*:docker:*:*

CVSS Data

CVSS version used by this source: 4.0

9.0CRITICAL

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 16th percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/autobrr/quiFixed in: 1.15.0

Vendor Advisories (1)

goGHSA-h8vw-ph9r-xpchcritical

qui CORS Misconfiguration: Arbitrary Origins Trusted

Mar 19, 2026

References

github.com / autobrr/qui/commit/424f7a0de089dce881e8bbecd220163a78e0295f
Patch
github.com / autobrr/qui/security/advisories/GHSA-h8vw-ph9r-xpch
Vendor Advisory