CVE-2026-86111
MEDIUM6.5CVSS v3
—CVSS v2
0.25%
EPSS (exploit probability)
CWE-639CWE
Description
BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.