Impact
A vulnerability in the ExampleDetail endpoint of Doccano allows remote attackers to bypass access controls and retrieve example data without proper authorization. This improper access control provides a path for confidential information exposure and could be combined with other weaknesses to further compromise data integrity or confidentiality. The weakness is tied to CWE-266 (Incorrect Authorization) and CWE-284 (Improper Access Control).
Affected Systems
Doccano Open Source Annotation Tools for Machine Learning Practitioners and its Auto Labeling Pipeline Module to Annotate a Document Automatically are affected when installed in versions up to 1.8.5. The flaw resides in the /v1/projects/1/examples/ route and can be exploited on any instance of the affected product.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the moderate risk range. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, indicating a lower likelihood of widespread exploitation yet still providing a publicly available exploit. Attackers can launch the attack remotely, creating a realistic threat for systems exposed to untrusted networks or lacking strict endpoint controls. Given the moderate severity and the lack of a vendor response, the risk remains notable and should be addressed promptly.
OpenCVE Enrichment