{"id":"CVE-2018-1000843","aliases":["GHSA-p69g-f978-xxv9","PYSEC-2018-11"],"url":"https://o3.security/vulnerability/CVE-2018-1000843","summary":"Cross-Site Request Forgery (CSRF) in Luigi","details":"Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross ite Request Forgery (CSRF) vulnerability in API endpoint: /api/<method> that can result in Task metadata such as task name, id, parameter, etc. will be leaked to unauthorized users. This attack appear to be exploitable via The victim must visit a specially crafted webpage from the network where their Luigi server is accessible.. This vulnerability appears to have been fixed in 2.8.0 and later.","published":"2018-12-20T15:29:02.047Z","modified":"2026-07-08T11:47:54.768798Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"PyPI","name":"luigi","fixedVersion":"2.8.0"}],"fix":{"url":"https://github.com/spotify/luigi/pull/1870","label":"spotify/luigi#1870"},"references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/luigi-user/ZgfRTpBsVUY"},{"type":"EVIDENCE","url":"https://github.com/spotify/luigi/blob/2.7.9/luigi/server.py#L67"},{"type":"EVIDENCE","url":"https://github.com/spotify/luigi/pull/1870"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:47:54.768798Z"}}