Impact
Wiki.js up to and including version 2.5.314 omits page tags from authorization checks in several GraphQL resolvers. This omission lets an attacker query the list, tree, tags, searchTags, and links endpoints and retrieve metadata—titles, descriptions, paths, and tag information—of pages that should be protected. The vulnerability is a classic authorization bypass (CWE‑863) and can expose confidential content without proper authorization.
Affected Systems
The vulnerability affects the Requarks Wiki.js product, specifically release 2.5.314. No other releases are mentioned in the advisory as impacted.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The likely attack vector is sending unauthenticated GraphQL queries over HTTP, exploiting the missing tag checks to obtain restricted page metadata. The vulnerability is not listed in the CISA KEV catalog, so no documented exploits exist, but the absence of proper authorization remains a security risk.
OpenCVE Enrichment