GHSA-v853-p72q-4cfw
HIGHQuart 0.23.0 contains a stray debug statement (print(data)) inside Body.await in quart/wrappers/request.py. Any request whose body is awaited — await request.form, await request.getdata(), WTForms validateonsubmit(), etc. — has its raw, unparsed body printed to stdout, including plaintext form fields such as passwords and CSRF tokens. Confirmed present in 0.23.0, confirmed absent in 0.22.0.
// detailsIn src/quart/wrappers/request.py, Body.await accumulates the request body into a bytearray:
python data = bytearray() while not self.queue.empty(): data.extend(self.queue.getnowait()) print(data) # self.maxcontentlength ): raise RequestEntityTooLarge()
This fires for every request that awaits its body — the overwhelming majority of POST/PUT routes in a typical Quart app (form submissions, JSON APIs via request.getjson(), file uploads, etc.).
// poc- pip install quart==0.23.0 (requires Python 3.13+)
- Minimal route:
python @app.route("/login", methods=["POST"]) async def login(): formdata = await request.form ...
- Submit a POST with form data, e.g. a login form with staffid/password fields.
- Observe stdout: the full raw body is printed as bytearray(b'csrftoken=...&staffid=...&password=...').
Confirmed via source diff against 0.22.0's request.py, where this line does not exist.
// impactAny app that captures stdout in logs (terminal redirect, systemd/journald, Docker logs, cloud log aggregation, etc.) will have every submitted form body — including login credentials — written to logs in plaintext. This affects any Quart 0.23.0 app handling authentication or any sensitive form data, and is trivially triggerable by any user simply submitting a form (no attacker action required beyond normal use).