Impact
DeepTutor 1.4.0 contains an authorization bypass that arises when a user-controlled object identifier is passed to TurnRuntimeManager.regenerate_last_turn. By supplying a session_id belonging to another user, an attacker can invoke the regeneration operation on an arbitrary session, effectively taking control of that session. The vulnerability allows the attacker to access, modify, or delete the victim’s data, compromising confidentiality, integrity, and availability of the affected user’s session data.
Affected Systems
The affected product is DeepTutor version 1.4.0. Vendor information is not disclosed in the CVE, so all installations of this version are considered potentially impacted. No other vendor or product details are available.
Risk and Exploitability
The CVSS score is not provided and EPSS is not available, but the fact that a remote caller can trigger an operation on another user’s session indicates a high risk. The vulnerability can be exploited remotely by an attacker who can obtain or guess a valid session_id, which does not require local access or privileged user credentials. The vulnerability is not listed in CISA’s KEV catalog, but its impact and the ease of exploitation suggest it should be treated with priority.
OpenCVE Enrichment