bookwyrm vulnerability

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.

Published 5 Sep 2026Updated 5 Sep 20265 sources
CVSS 7.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.