Authentication Bypass in OpenSave by Liquid.co Allows Impersonation of Devices
CVE-2026-103397
6.3MEDIUM
What is CVE-2026-103397?
The OpenSave application, prior to version 2.4.0-beta.1, contains a vulnerability where sender identity validation in WAN relay requests is insufficient. This allows unpaired room members to impersonate legitimate paired devices by manipulating the RelayMessage's From field. Malicious actors who possess the room code can gain access, retrieve identifiers of paired peers from announcements, and issue forged requests that compromise protected sync routes, enabling unauthorized access to sensitive data, including save states, snapshots, and file operations.
Affected Version(s)
OpenSave 0 < 2.4.0-beta.1
