WhisperX tag archive

#state-mutating endpoints

This page collects WhisperX intelligence signals tagged #state-mutating endpoints. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-29 20:54:11 · GitHub Issues

1. CSRF Protection Absent on Key API Endpoints: Default Config Exposes Admin Actions to Malicious Requests

A security vulnerability has been identified in multiple state-mutating REST API endpoints under `/api/v1/`, where Cross-Site Request Forgery (CSRF) token validation is not enforced when the default configuration `WTF_CSRF_ENABLED` is set to `False`. The flaw affects administrative functions including dashboard saves, ...