GHSA-c8qj-jx8j-fg2wCritical▾ MidnightDotVVM: Missing authorization in AuthorizeActionFilter
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
All users of the AuthorizeActionFilter class are affected. The AuthorizeActionFilter simply does nothing, no “hacking” is needed to bypass the filter.
DotVVM 4.3.15, 4.2.11 and 5.0.0-preview09 fix this.
As a workaround, you can use the AuthorizeAttribute instead. It implements the same interfaces (correctly). Note that is it deprecated for unrelated reasons, feel free to suppress the warning when using it as action filter.
DotVVM < 4.2.11DotVVM > 4.3.0-preview01-final, < 4.3.15DotVVM >= 5.0.0-preview01-final, < 5.0.0-preview09-finalUpgrade to a patched release:
DotVVM 4.2.11DotVVM 4.3.15DotVVM 5.0.0-preview09-finalConnected by shared product, vendor, weakness, or advisory.
CVE-2026-57578Critical· 9.2DotVVM is an open source MVVM framework for web applications
GHSA-c2g3-c4gc-w5wgHighReDoS in DotVVM routing
GHSA-2rm3-333w-xvc4Medium· 5.3DotVVM: Unrestricted file upload
CVE-2026-57581Medium· 5.3DotVVM is an open source MVVM framework for web applications
CVE-2026-57577High· 8.2DotVVM is an open source MVVM framework for web applications
CVE-2024-0829Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0