Логотип exploitDog
bind:CVE-2026-5022
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-5022

Количество 2

Количество 2

nvd логотип

CVE-2026-5022

12 дней назад

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.

EPSS: Низкий
github логотип

GHSA-jvx2-jcjj-x36h

12 дней назад

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5022

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.

0%
Низкий
12 дней назад
github логотип
GHSA-jvx2-jcjj-x36h

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.

0%
Низкий
12 дней назад

Уязвимостей на страницу