Impact
Typemill before version 2.26.0 contains an authorization bypass in the media file download route that allows an attacker to retrieve restricted files without authentication. The flaw relies on path normalization, enabling the traversal of role‑based checks by using dot‑slash prefixes, double slashes, or percent‑encoded URLs. This results in unauthorized file disclosure, compromising the confidentiality of protected data. The vulnerability is identified as CWE‑863, an authorization bypass weakness.
Affected Systems
The affected product is Typemill, versions older than 2.26.0. Any installation that still uses these versions is susceptible to the attack as the media file download route remains publicly reachable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity weakness. The EPSS score is currently unavailable, so the exact exploitation probability is uncertain, but the absence of a KEV listing suggests no widespread active exploitation is reported. Attackers can exploit the vulnerability by issuing HTTP requests directly to the media download endpoint, substituting equivalent URL forms to bypass access controls and download protected files.
OpenCVE Enrichment