OpenReplay是OpenReplay公司开源的一款开发人员友好的、自托管的会话重播软件。 OpenReplay 1.22.0版本至1.27.0之前版本存在授权问题漏洞,该漏洞源于会话路径参数验证不当,导致未验证会话是否属于已授权项目,从而允许任何经过身份验证的低权限用户读取其他租户的前15秒会话重放录制数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| openreplay | openreplay | >= 1.22.0, < 1.27.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| openreplay | openreplay | >= 1.22.0, < 1.27.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55879 | 9.3 CRITICAL | OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover |
| CVE-2026-55880 | 7.1 HIGH | OpenReplay: Cross-user IDOR in notes and dashboard widgets |
| CVE-2026-57230 | 5.4 MEDIUM | OpenReplay: Authenticated ClickHouse SQL injection via session search |
No comments yet