highCVSS 7.5Vulnerability

GHSA-v853-p72q-4cfw

### Summary Quart 0.23.0 contains a stray debug statement (`print(data)`) inside `Body.__await__` in `quart/wrappers/request.py`. Any request whose body is awaited — `await request.form`, `await request.get_data()`, WTForms `validate_on_submit()`, etc. — has its raw, unparsed body printed to stdout, including plaintext form fields such as passwords and CSRF tokens. Confirmed present in 0.23.0, confirmed absent in 0.22.0. ### Details In `src/quart/wrappers/request.py`, `Body.__await__` accumulates the request body into a bytearray: ​```python data = bytearray() while not self._queue.empty(): data.extend(self._queue.get_nowait()) print(data) # <-- not present in 0.22.0 if ( self._max_content_length is not None and len(data) > self._max_content_length ): raise RequestEntityTooLarge() ​``` This fires for every request that awaits its body — the overwhelming majority of POST/PUT routes in a typical Quart app (form submissions, JSON APIs via `request.get_json()`, file uploads, etc.). ### PoC 1. `pip install quart==0.23.0` (requires Python 3.13+) 2. Minimal route: ​```python @app.route("/login", methods=["POST"]) async def login(): form_data = await request.form ... ​``` 3. Submit a POST with form data, e.g. a login form with `staff_id`/`password` fields. 4. Observe stdout: the full raw body is printed as `bytearray(b'csrf_token=...&staff_id=...&password=...')`. Confirmed via source diff against 0.22.0's `request.py`, where this line does not exist. ### Impact Any app that captures stdout in logs (terminal redirect, systemd/journald, Docker logs, cloud log aggregation, etc.) will have every submitted form body — including login credentials — written to logs in plaintext. This affects any Quart 0.23.0 app handling authentication or any sensitive form data, and is trivially triggerable by any user simply submitting a form (no attacker action required beyond normal use).

Properties

summary
Quart leaks raw request body (incl. plaintext passwords) to stdout via stray debug print in Body.__await__
severity
high
cvss_score
7.5
retrieved_at
2026-10-05T22:59:07+00:00
ghsa_published
2026-10-05T22:49:44Z
source_url
https://github.com/advisories/GHSA-v853-p72q-4cfw
ghsa_updated
2026-10-05T22:49:45Z
ghsa_id
GHSA-v853-p72q-4cfw
last_source
GitHub Advisory Database
cve_id
GHSA-v853-p72q-4cfw
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
signal_observed_at
2026-10-05T22:59:07+00:00
is_ghsa_only
true

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Insertion of Sensitive Information into Log File

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/quart

AFFECTS (1)

→[Software]pip/quart

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-v853-p72q-4cfw (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal