Impact
Mooncake Store master through version 0.3.13.post1 has a missing authorization flaw that allows attackers without credentials to call RPC methods on the coro_rpc port. By invoking CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete, an adversary can create new replication tasks, steal existing ones, or falsely mark tasks as completed. The vulnerability enables the attacker to hijack replication queues and record replication that never occurred, compromising data integrity.
Affected Systems
The affected system is Mooncake Store by kvcache-ai. All releases up to and including 0.3.13.post1 are impacted. Users running these versions should verify their deployment against the identified code paths.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely through the exposed RPC interface, assuming network connectivity to the coro_rpc port. The lack of authentication checks makes exploitation straightforward for any host that can reach this port.
OpenCVE Enrichment