GHSA-v853-p72q-4cfw: CSRF
Summary Quart 0.23.0 contains a stray debug statement (print(data)) inside Body.await in quart/wrappers/request.py. Any request whose body is awaited — await request.form, await request.getdata(), WTForms validateonsubmit(), etc. — has its raw, unparsed body printed to stdout, including plaintext form fields such as passwords and CSRF tokens. Confirmed present in 0.23.0, confirmed absent in 0.22.0.
Details In src/quart/wrappers/request.py, Body.await accumulates the request body into a bytearray:
python data = bytearray() while not self.queue.empty(): data.extend(self.queue.getnowait()) print(data) # <-- not present in 0.22.0 if ( self.maxcontentlength is not None and len(data) > self.maxcontentlength ): raise RequestEntityTooLarge()
This fires for every request that awaits its body — the overwhelming majority of POST/PUT routes in a typical Quart app (form submissions, JSON APIs via request.getjson(), file uploads, etc.).
PoC 1. pip install quart==0.23.0 (requires Python 3.13+) 2. Minimal route: python @app.route("/login", methods=["POST"]) async def login(): formdata = await request.form ... 3. Submit a POST with form data, e.g. a login form with staffid/password fields. 4. Observe stdout: the full raw body is printed as bytearray(b'csrftoken=...&staffid=...&password=...').
Confirmed via source diff against 0.22.0's request.py, where this line does not exist.
Impact Any app that captures stdout in logs (terminal redirect, systemd/journald, Docker logs, cloud log aggregation, etc.) will have every submitted form body — including login credentials — written to logs in plaintext. This affects any Quart 0.23.0 app handling authentication or any sensitive form data, and is trivially triggerable by any user simply submitting a form (no attacker action required beyond normal use).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/quartto a version that resolves this vulnerability.Fixed in 0.23.1 - Upgrade
Upgrade
Quartto a version that resolves this vulnerability.Fixed in 0.22.0