PT-2026-53320 · Unknown · Deepmyst Mysti
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
DeepMyst Mysti version 0.4.0
Description
An improper authorization issue exists within the Contact Tracking component. The flaw is located in the
isTrackedConversation() function of the src/managers/ChannelBridge.ts file. A remote attacker can exploit this by manipulating the channelType argument. The attack requires a high degree of complexity and is considered difficult to execute.Recommendations
Install patch 9b4aff0f106db424aa45a35aa89dd0b8f2eb9a48 for version 0.4.0.
As a temporary mitigation, restrict access to the
isTrackedConversation() function.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Deepmyst Mysti