Impact
The vulnerability resides in the cu:silicon edit endpoint’s create_app function in views.py, where authentication checks are omitted. An attacker who reaches this endpoint over the network can invoke the create_app operation without proving identity, enabling the creation of new application contexts or other privileged actions. This breach of authentication provides the attacker with unauthorized access to functionality that the system intended to protect.
Affected Systems
cu:silicon components up through version 0.1.5 are vulnerable. Any deployment that has not upgraded beyond 0.1.5 and exposes the edit endpoint is susceptible to this issue.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability, but the publicly available exploit and the ability to perform the attack remotely increase the practical risk. The EPSS score is not reported, and the issue is not currently listed in CISA’s KEV catalog. Because the vulnerability can be triggered from anywhere with network access, any exposed instance of the affected endpoint represents a potential attack surface until a patch or mitigation is applied.
OpenCVE Enrichment