Impact
The vulnerability, identified as CWE-287, lies in the getInternalTaskSession, getAuthSession, requireUserAuth, requireProjectAuth, and requireProjectAuthLight functions of the Internal Task Header Handler. By manipulating the x‑internal‑user‑id header, an attacker can bypass the authentication check and obtain access to protected internal task resources. This unauthorized access can expose confidential information or enable privileged operations within the affected project.
Affected Systems
waooAI waoowaoo component versions up to and including 0.4.1 are affected. The flaw is present in the src/lib/api-auth.ts file of the Internal Task Header component.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score of <1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Remote exploitation is possible when an attacker crafts a request that includes a forged x‑internal‑user‑id header, implying a network-borne attack vector.
OpenCVE Enrichment