VDB
Sign up
—0.0

PYSEC-2026-1924

sigstore CSRF possibility in OIDC authentication during signing

Quick fix

PYSEC-2026-1924 — sigstore: upgrade to the fixed version with the command below.

pip install --upgrade 'sigstore>=4.2.0'

Details

### Summary

The sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery.

### Details

`_OAuthSession` creates a unique "state" and sends it as a parameter in the authentication request but the "state" in the server response seems not not be cross-checked with this value.

Fix should be fairly trivial.

### Impact

This should be low impact: A man-in-the middle attacker could trick a sigstore-python user into signing something with an identity controlled by the attacker (by returning the response to an authentication request they created). This would be quite confusing but not dangerous.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/sigstore
Introduced in: 0Fixed in: 4.2.0
Fixpip install --upgrade 'sigstore>=4.2.0'

References