---
id: CVE-2025-3660
title: >-
  Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken
  access control vulnerability that allows authenticated users to access other
  users' pet data by exploiting missing ownership verification
summary: >-
  Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken
  access control vulnerability that allows authenticated users to access other
  users' pet data by exploiting missing ownership verification. Attackers can
  send requ…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-612
vendor: petlibro
product: petlibro
affected:
  - petlibro <= 1.7.31
published: '2026-01-04'
updated: '2026-07-20'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-3660'
references:
  - url: 'https://bobdahacker.com/blog/petlibro'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/petlibro-smart-pet-feeder-platform-through-broken-access-control-via-api-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0021
epssPercentile: 0.1149
ingestedAt: '2026-07-20T23:44:02.103Z'
---

## Overview

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.

## Affected

- `petlibro <= 1.7.31`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
