CVE-2026-5128

10.0 CRITICAL
Published: March 30, 2026 Modified: March 30, 2026
View on NVD

Description

A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker can send a request to the /usersย API endpoint to retrieve highly sensitive Steam account data, including the account username, password, identity secret, and shared secret. In addition, application logs expose authentication artifacts such as access tokens, refresh tokens, and session identifiers. This information allows an attacker to generate valid Steam Guard (2FA) codes, hijack authenticated sessions, and obtain full control over the affected Steam account, including unauthorized access to inventory and trading functionality. No fix is available because the repository is archived and no longer maintained.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/arthurfiorette/steam-trader
Source: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

1 reference(s) from NVD

Quick Stats

CVSS v3 Score
10.0 / 10.0
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)