{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/cheshire-cat-ai/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cheshire_cat_ai:cheshire_cat_ai:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90579"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cheshire Cat AI (\u003c= 1.9.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","webserver"],"_cs_type":"advisory","_cs_vendors":["Cheshire Cat AI"],"content_html":"\u003cp\u003eCheshire Cat AI version 1.9.2 and earlier contains an authentication bypass vulnerability due to flawed logic in the _authorize_http_key function located in core/cat/factory/custom_auth_handler.py. An attacker can exploit this by manipulating the user_id argument to bypass authentication mechanisms entirely. The vulnerability allows remote, unauthenticated access to the application, potentially leading to unauthorized operations within the AI framework. As the vulnerability has been publicly disclosed and the project maintainers have not yet provided a patch, installations of Cheshire Cat AI are at risk of exploitation. Defenders should monitor web server access logs for anomalous requests to API endpoints that rely on the affected custom authentication handler.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify instances of Cheshire Cat AI exposed to the internet.\u003c/li\u003e\n\u003cli\u003eAttacker locates the application endpoint that utilizes the core/cat/factory/custom_auth_handler.py authentication logic.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the affected function _authorize_http_key.\u003c/li\u003e\n\u003cli\u003eAttacker injects a manipulated user_id argument into the request parameters to bypass authentication checks.\u003c/li\u003e\n\u003cli\u003eThe application fails to validate the identity of the requester, granting the attacker an authenticated session.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the gained session to perform unauthorized API calls or interact with the AI logic.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved, which may include data exfiltration or arbitrary command execution within the application context.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote, unauthenticated attacker to bypass authentication controls, potentially gaining full control over the Cheshire Cat AI instance. This could lead to the exposure of sensitive AI models, processed data, and underlying system commands. The vulnerability affects all users running versions 1.9.2 and earlier, as there is currently no vendor-provided patch.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests directed at authentication endpoints containing non-standard or unexpected user_id values.\u003c/li\u003e\n\u003cli\u003eImplement strict network access controls to limit exposure of the Cheshire Cat AI interface to trusted networks only until a security update is released.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of the custom authentication handler and consider implementing external authentication proxies (e.g., OAuth2, OIDC) as an interim compensating control.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T19:26:11Z","date_published":"2026-09-13T19:26:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cheshire-cat-auth-bypass/","summary":"An unauthenticated remote code execution vulnerability in Cheshire Cat AI version 1.9.2 and earlier stems from improper validation of the user_id argument within the custom authentication handler.","title":"Authentication Bypass in Cheshire Cat AI via Custom Auth Handler","url":"https://feed.craftedsignal.io/briefs/2026-09-cheshire-cat-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cheshire Cat AI","version":"https://jsonfeed.org/version/1.1"}