Impact
The vulnerability in exo‑explore exo 1.0.69 allows a remote attacker to call the GET /state and DELETE /instance/{instance_id} endpoints without authentication. The lack of authentication permits the attacker to read state information and delete or alter instances, effectively escalating privileges within the application. This flaw is classified as CWE‑306, an authentication bypass weakness.
Affected Systems
exo‑explore exo 1.0.69.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote access over HTTP to the unauthenticated /state and /instance endpoints.
OpenCVE Enrichment