CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-54635

CVE-2026-54635: Authentication Bypass via Custom Webhook Paths in pytonapi

Amit Schendel
Amit Schendel
Senior Security Researcher

Jul 28, 2026·6 min read·34 visits

Executive Summary (TL;DR)

Unauthenticated remote attackers can bypass webhook authorization and spoof transaction events by exploiting a fail-open design when custom registration paths are configured in the pytonapi dispatcher.

An authentication bypass vulnerability exists in the pytonapi library when custom paths are registered in the TonapiWebhookDispatcher. The application fails to retrieve or store secure tokens for custom paths, leading to a fail-open authorization check that allows unauthenticated remote attackers to send spoofed webhook events directly to internal handlers.

Vulnerability Overview

The pytonapi library provides a Python Software Development Kit (SDK) for TONAPI, enabling developer integration with The Open Network (TON) blockchain. The SDK includes a webhook dispatcher class, TonapiWebhookDispatcher, designed to receive and verify asynchronous event notifications such as ledger transactions and smart contract deployments. To ensure request integrity, the dispatcher relies on authentication tokens supplied via the HTTP Authorization header of incoming POST requests.

When developers implement the default webhook routing configuration, the library registers and verifies paths correctly. However, the dispatcher allows developers to register custom endpoint paths using the path keyword parameter on handlers. If a custom path is specified, the internal initialization routine neglects to populate the corresponding verification tokens for that specific route.

This omission results in a logical disconnect within the routing and verification pipeline. Incoming requests directed to custom paths bypass the authentication guard entirely because of a fail-open execution design. An unauthenticated remote attacker can exploit this condition to inject forged transaction payloads directly into user-defined event handlers.

Root Cause Analysis

The flaw resides in the initialization sequence within pytonapi/webhook/dispatcher.py. During the invocation of the setup() method, the dispatcher iterates over registered event types to register hook endpoints with the upstream TONAPI client. In versions prior to 2.2.1, the method retrieves tokens solely for the hardcoded suffixes defined in self.DEFAULT_SUFFIXES.

These default suffixes correspond to standard endpoints like /hook/account-tx. If a handler is registered with a custom path (such as /hook/custom), the dispatcher records the custom path for routing but fails to request or associate a secure authorization token with this path inside the self._tokens dictionary. As a consequence, the token lookup table lacks keys representing custom-registered paths.

When the dispatcher receives an HTTP POST request, the process() method retrieves the target route and performs a lookup: expected_token = self._tokens.get(path). For custom paths, this lookup returns None. The validation logic is structured as a conditional check: if expected_token is not None and authorization != f"Bearer {expected_token}": raise TONAPIError(...). Because the expected token is None, the entire conditional block is evaluated as False, bypassing the validation check and executing the handler.

Code Analysis

The vulnerable implementation of the dispatcher setup sequence relies on default suffixes to create webhook tokens:

# Vulnerable initialization block in pytonapi <= 2.2.0
suffix = self.DEFAULT_SUFFIXES[event_type]
local_path = self._path + suffix
webhook = await self._client.ensure(f"{self._url}{suffix}")
self._tokens[local_path] = webhook.token  # Token populated only for default suffix

The matching authentication logic inside process() relies on a fail-open validation approach:

# Fail-open checking logic in process()
expected_token = self._tokens.get(path)  # Resolves to None for custom paths
 
if expected_token is not None and authorization != f"Bearer {expected_token}":
    raise TONAPIError("Invalid webhook token")  # Skipped entirely

The remediation applied in version 2.2.1 modifies the setup loop to iterate over all distinct paths defined across all handlers:

# Remedied initialization loop in pytonapi 2.2.1
for local_path in sorted({path for _, _, path in handlers}):
    webhook = await self._client.ensure(self._endpoint_for_path(local_path))
    self._tokens[local_path] = webhook.token  # Token is correctly generated and mapped

This structural shift ensures that every custom route receives a dedicated token. The reverse path mapper was also refactored to handle multiple paths reliably.

Exploitation and Attack Methodology

To exploit this vulnerability, an attacker must first locate an application running a vulnerable version of pytonapi that registers custom paths for incoming webhook payloads. Because the custom endpoint must be publicly accessible to receive updates from the TONAPI services, the endpoint is exposed directly to the internet.

No specialized exploitation tools are required to trigger the vulnerability. The attacker can structure an HTTP POST request targeting the custom URL path. The request body must contain a structured JSON payload mimicking a legitimate blockchain event, such as a transaction receipt.

Because of the lack of token validation, the attacker does not need to supply a valid Authorization header. Sending the request with no authorization header, or with a randomized dummy string, succeeds. The server processes the fake transaction payload as legitimate, triggering the application's processing routines which can lead to spoofed ledger deposits.

Below is a schematic mapping of the vulnerability logical flow:

Impact Assessment

The vulnerability allows complete bypass of authentication controls, leading to a High integrity impact. An attacker cannot read sensitive configuration values directly through this endpoint, keeping confidentiality impact low or none. However, the integrity of application-level transactions is completely compromised.

In applications handling financial actions or cryptocurrency exchanges, webhook dispatchers are utilized to verify user deposits and payments. Spoofing these webhooks allows attackers to claim credit for arbitrary transactions without actually depositing funds onto the blockchain. This can lead to severe financial discrepancies.

This logical flaw is classified under CWE-287 (Improper Authentication) and maps to MITRE ATT&CK technique T1190 (Exploit Public-Facing Application). Because it requires zero interaction from users and can be performed with low complexity over standard HTTP, the CVSS v3.1 score is calculated as 7.5 (High).

Remediation and Mitigation

The definitive resolution for this issue is to upgrade the pytonapi installation to version 2.2.1 or later. This version ensures proper token generation and enforcement for all custom paths. The package can be upgraded from PyPI using standard package management utilities.

If updating the dependency is not immediately possible, developers must mitigate the risk by eliminating the use of custom paths. Removing the path argument from webhook decorator registrations forces the library to fall back onto its default suffixes, which are correctly authenticated even in vulnerable library versions.

Additionally, network-level ingress filtering can be implemented to restrict incoming requests to the webhook endpoints. Standard TONAPI webhook requests originate from known, documented server IP ranges, allowing developers to construct firewall or reverse proxy rules to drop requests originating from unauthorized addresses.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Systems

pytonapi Webhook Dispatcher Component

Affected Versions Detail

Product
Affected Versions
Fixed Version
pytonapi
nessshon
>= 2.0.0, < 2.2.12.2.1
AttributeDetail
CWE IDCWE-287 (Improper Authentication)
Attack VectorNetwork
CVSS v3.1 Score7.5 (High)
ImpactHigh Integrity Compromise
Exploit StatusPoC Available
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1078Valid Accounts
Initial Access
CWE-287
Improper Authentication

The software does not prove, or insufficiently proves, the identity of an actor before granting access to resources.

Known Exploits & Detection

GitHubOfficial Proof-of-Concept code and technical analysis in advisory.

Vulnerability Timeline

Vulnerability patched in commit 854222b7ee68d3fb7b4d6d899d200f388483bd86
2026-06-07
Advisory GHSA-3fcr-jvgp-7f58 published and CVE-2026-54635 assigned
2026-07-28

References & Sources

  • [1]GitHub Security Advisory GHSA-3fcr-jvgp-7f58
  • [2]GitHub Patch Commit
  • [3]pytonapi v2.2.1 Release Details

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 6 hours ago•CVE-2026-107844
5.3

CVE-2026-107844: Path Traversal Vulnerability in Contao ImagesController

A path traversal vulnerability (CWE-22) in Contao CMS allows unauthenticated remote attackers to bypass directory boundary restrictions in ImagesController and access files within the project directory.

Amit Schendel
Amit Schendel
8 views•5 min read
•about 8 hours ago•CVE-2026-107848
3.5

CVE-2026-107848: Cross-Site Request Forgery (CSRF) in Contao Backend Actions via GET Requests

Contao Open Source CMS versions 4.0.0 through 5.3.49 and 5.4.0-RC1 through 5.7.11 contain a Cross-Site Request Forgery (CSRF) vulnerability in backend parameter handling. The `RequestTokenListener` component validates anti-CSRF tokens solely for HTTP POST requests, while GET-based declarative guards run only when an `act` parameter is present in the query string. Consequently, custom backend actions dispatched via alternative parameters such as `key=` can execute without CSRF token verification when triggered by an authenticated user.

Amit Schendel
Amit Schendel
7 views•5 min read
•about 9 hours ago•CVE-2026-107843
5.3

CVE-2026-107843: Unthrottled Activation Email Resend and Account Enumeration in Contao CMS

Contao CMS versions 4.1.0 through 5.3.49 and 5.4.0-RC1 through 5.7.11 fail to validate form submission tokens and enforce rate limiting when processing activation email resend requests via HTTP POST, enabling resource exhaustion and account state enumeration.

Amit Schendel
Amit Schendel
8 views•4 min read
•about 10 hours ago•CVE-2026-107842
5.3

CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module

An information disclosure vulnerability in Contao CMS allows unauthenticated site visitors to view protected page titles, URLs, and text excerpts through search queries when protected page indexing is disabled after previously being enabled.

Amit Schendel
Amit Schendel
9 views•4 min read
•about 11 hours ago•GHSA-G38J-7V97-X298
6.5

GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation

In Vikunja prior to version 2.6.0, relation creation via the CalDAV endpoint fails to invoke the TaskRelation.CanCreate authorization check. This missing access control allows an authenticated user to establish unauthorized relationships and perform write operations against any task, provided its unique identifier (UID) is known.

Alon Barad
Alon Barad
10 views•5 min read
•about 12 hours ago•GHSA-3HC7-R24J-RPWC
6.8

GHSA-3hc7-r24j-rpwc: Cross-Project Task Disclosure via Subtask Expansion in Vikunja

A cross-project information disclosure vulnerability in Vikunja allows authenticated users with read access to one project to view private task details from unauthorized projects via subtask expansion parameters.

Alon Barad
Alon Barad
9 views•5 min read