Impact
The vulnerability is in the _authorize_http_key function of the custom_auth_handler module. It causes the function to skip authentication checks to the application's resources and represents improper authentication and missing credential management. The bypass can be triggered over HTTP and does not require prior access to the system, allowing remote exploitation.
Affected Systems
All installations of Cheshire Cat AI up to and including version 1.9.2 are vulnerable.
Risk and Exploitability
6.9 indicates moderate severity. EPSS score of < 1% indicates a low probability of exploitation, but the exploit has been publicly disclosed and can be used by attackers. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited widespread exploitation to date, but the public availability of the exploit means the risk remains significant. An attacker can initiate the exploit remotely via HTTP requests, and no privileged access is required.
OpenCVE Enrichment