VulnSea

bookwyrm vulnerabilities

CVEs whose affected-version data names the bookwyrm package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-86113Medium· 6.5PoC
2w ago

BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records

BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite …

Twilightbookwyrm-social · bookwyrmEPSS 0.24%via NVD
CVE-2026-86112Medium· 5.4
2w ago

BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access

BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can PO…

Sunlitbookwyrm-social · bookwyrmEPSS 0.18%via NVD
CVE-2026-86111Medium· 6.5PoC
2w ago

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can acce…

Twilightbookwyrm-social · bookwyrmEPSS 0.25%via NVD
bookwyrm vulnerabilities (CVEs) · VulnSea