Impact
Forem, an open‑source community platform, contains a flaw that lets a maliciously crafted email address circumvent domain allowlist or denylist checks. The vulnerability allows an attacker to receive invitations to invite‑only deployments and gain access that should otherwise be restricted. The weakness is a classic authorization bypass, classified as CWE‑287.
Affected Systems
The issue affects all installations of Forem running a version prior to commit a2ab6d4. Any deployment that relies on Forem’s built‑in email invite system is vulnerable. The product is identified as forem:forem.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity impact. EPSS is less than 1 %, suggesting current exploitation is unlikely, and the vulnerability is not yet listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves forging an email address that passes the domain filter and using it in the invitation process to obtain unauthorized access to the community.
OpenCVE Enrichment