GHSA-phg3-p22v-rp9qHighCVSS 6.5

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint,...

Published
September 5, 2026
Last Modified
September 5, 2026

🔗 CVE IDs covered (1)

📋 Description

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.

🔗 References (7)