{"id":"CVE-2024-25169","aliases":["GHSA-qp56-82vp-xqgv","PYSEC-2026-1627"],"title":"Mezzanine allows attackers to bypass access control mechanisms","summary":"Mezzanine allows attackers to bypass access control mechanisms","severity":"medium","vendor":"mezzanine","product":"mezzanine","ecosystem":"pip","affected":["mezzanine <= 6.0.0"],"published":"2024-02-28","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-qp56-82vp-xqgv","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-25169"},{"url":"https://github.com/shenhav12/CVE-2024-25169-Mezzanine-v6.0.0"},{"url":"https://github.com/stephenmcd/mezzanine"},{"url":"https://ibb.co/JKh4hmD"},{"url":"https://ibb.co/Pt9qd8t"},{"url":"https://ibb.co/hLLPTVp"},{"url":"https://ibb.co/rfrKj3r"}],"tags":["osv","pip","exploit-available"],"epss":0.01105,"epssPercentile":0.64374,"ingestedAt":"2026-07-08T18:25:52.462Z","exploits":{"github":1,"githubRepos":["https://github.com/shenhav12/CVE-2024-25169-Mezzanine-v6.0.0"],"checkedAt":"2026-09-24T07:52:51.162Z"},"exploitAvailable":true,"slug":"CVE-2024-25169","body":"## Overview\n\nAn issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.\n\n## Affected packages\n\n- `mezzanine <= 6.0.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":27.5,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4702,"id":"CVE-2024-25169","ts":1788887200275,"field":"exploit_available","old":"false","new":"true"},{"seq":3585,"id":"CVE-2024-25169","ts":1788886316767,"field":"exploit_available","old":"true","new":"false"},{"seq":2439,"id":"CVE-2024-25169","ts":1788882985509,"field":"exploit_available","old":"false","new":"true"},{"seq":1468,"id":"CVE-2024-25169","ts":1788882398799,"field":"exploit_available","old":"true","new":"false"},{"seq":582,"id":"CVE-2024-25169","ts":1788881835439,"field":"exploit_available","old":"false","new":"true"}]}