{"id":"CVE-2026-36453","title":"Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1","summary":"Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","cwe":["CWE-425"],"vendor":"Rhymix","product":"Rhymix","affected":["Rhymix < 2.1.31"],"published":"2026-09-13","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-36453","references":[{"url":"https://github.com/rhymix/rhymix/commit/f131a616eb990e2b070a8381c3106ae979d40989","label":"cve@mitre.org"},{"url":"https://rhymix.org/community/1932364","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.0027,"epssPercentile":0.17087,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T15:52:49.365380Z"},"ingestedAt":"2026-09-14T15:23:07.469Z","slug":"CVE-2026-36453","body":"## Overview\n\nRhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}