Description
A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The reported GitHub issue was closed automatically due to inactivity.
Published: 2026-09-18
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authentication bypass in the dependencies.py module of the FastAPI component of Forget-C's Jellyfish AI Short Drama Studio. Because the file lacks proper authentication checks, an attacker can invoke protected endpoints without credentials, effectively gaining unauthorized access. This flaw could allow the attacker to read or manipulate data, or carry out further actions depending on the exposed API.

Affected Systems

The flaw affects Forget-C's Jellyfish AI Short Drama Studio in versions 0.1.0‑alpha through 0.3.2, i.e., 0.1.0‑alpha, 0.2.0, 0.3.0, 0.3.1, and 0.3.2. Users running any of these releases are potentially exposed unless authentication is piloted by external measures.

Risk and Exploitability

The CVSS score for this issue is 6.9, which places it in the “Medium” severity range, and the EPSS score is less than 1%, indicating a low anticipated exploitation probability. The vulnerability is not listed in the CISA KEV catalog. However, exploitability is high from a remote standpoint, with attackers able to trigger the harmful behavior over the network, assuming the vulnerable API is exposed. The confusion around missing authentication is a classic authentication–authorization weakness (CWE‑287, CWE‑306). Combining the moderate CVSS with a low EPSS still warrants timely remediation due to the potential for unauthorized data and system manipulation.

Generated by OpenCVE AI on September 19, 2026 at 16:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a version of Jellyfish AI Short Drama Studio that includes the authentication logic in dependencies.py, for example the latest stable release that resolves the issue.
  • If an updated release is unavailable, secure the exposed API endpoints by configuring the reverse proxy or load balancer to require authentication—such as HTTP basic auth, OAuth, or JWT—before requests reach the FastAPI application.
  • Conduct a code audit of the FastAPI dependencies and verify that authentication middleware is correctly applied to all protected routes, ensuring that no route can bypass the authentication layer.

Generated by OpenCVE AI on September 19, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The reported GitHub issue was closed automatically due to inactivity.
Title Forget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authentication
First Time appeared Forget-c
Forget-c jellyfish Ai Short Drama Studio
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:forget-c:jellyfish_ai_short_drama_studio:*:*:*:*:*:*:*:*
Vendors & Products Forget-c
Forget-c jellyfish Ai Short Drama Studio
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Forget-c Jellyfish Ai Short Drama Studio
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:00:38.554Z

Reserved: 2026-09-18T09:43:25.261Z

Link: CVE-2026-93559

cve-icon Vulnrichment

Updated: 2026-09-22T15:00:34.339Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:17:06.473

Modified: 2026-09-22T16:18:13.477

Link: CVE-2026-93559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function