Sveltycms · Sveltycms · CVE-2026-93504
**Name of the Vulnerable Software and Affected Versions**
SveltyCMS version 0.0.6
**Description**
Improper access controls exist within the User Attribute Update Endpoint, specifically affecting the file `src/routes/api/[...path]/+server.ts`. This flaw allows a remote attacker to manipulate the system due to insufficient authorization checks.
**Recommendations**
Apply patch 05b4f9efeb79e9d72a693232334d7529687f896f for version 0.0.6.