PT-2026-76826 · Git+1 · Typemill
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Typemill versions prior to 2.26.0
Description
An authorization bypass exists in the media file download route. Unauthenticated attackers can access restricted files by submitting path-equivalent URL variants. By using normalized path forms, such as dot-slash prefixes, double slashes, or percent-encoded sequences, attackers can bypass role-based restriction checks. This occurs because the filesystem resolves the request to the protected file despite the security checks, allowing unauthorized file downloads without credentials.
Recommendations
Update Typemill to version 2.26.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typemill