BookWyrm 0.9.1 及之前版本在“收藏”和“取消收藏”视图中未能正确校验用户的可见性权限,使得经过身份验证的攻击者能够收藏或取消收藏其无权访问的“仅限关注者”或“直接消息”状态。攻击者可以通过向收藏端点 POST 状态 ID 来创建未授权的交互,触发 ActivityPub 广播,并通过响应的差异枚举私有状态 ID。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| bookwyrm-social | bookwyrm | ≤ 0.9.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bookwyrm-social | bookwyrm | 0 ~ 0.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86113 | 6.5 MEDIUM | BookWyrm through 0.9.1 Insecure Direct Object Reference in edit-readthrough Allows Tamperi |
| CVE-2026-86111 | 6.5 MEDIUM | BookWyrm through 0.9.1 Insecure Direct Object Reference in EditStatus Exposes Followers-On |
No comments yet