Impact
The vulnerability resides in the stablePublicIdFromStorageKey function of the Media Handler component of waooAI waoowaoo. By manipulating the storageKey argument, an attacker can bypass normal authorization checks and obtain media resources that should be restricted. This leads to unauthorized disclosure of media content and potentially other sensitive data associated with those resources. The weakness is described as improper authorization, corresponding to CWE‑266 and CWE‑285. While the CVE notes that exploitation is difficult and requires a high level of complexity, it also documents that an exploit has been made public, underscoring that a determined adversary can craft a remote attack that subverts access controls.
Affected Systems
The flaw affects deployments of waooAI waoowaoo with version numbers up to and including 0.4.1. Any installation that incorporates the Media Handler component – particularly those exposing media endpoints that accept a storageKey parameter – is vulnerable if the package has not been updated beyond 0.4.1. Earlier versions contain the same risky implementation and therefore remain exposed.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, and the EPSS score of less than 1 % suggests a low expected exploitation rate in the wild. Nonetheless, the public availability of an exploit and the remote nature of the attack mean that affected systems face a tangible risk. The vulnerability is not listed in the CISA KEV catalog, but because it grants unauthorized access to media data, it should be treated as a potential threat until a vendor update or alternative mitigation is applied.
OpenCVE Enrichment