Impact
The vulnerability is an authentication bypass in the dependencies.py module of the FastAPI component of Forget-C's Jellyfish AI Short Drama Studio. Because the file lacks proper authentication checks, an attacker can invoke protected endpoints without credentials, effectively gaining unauthorized access. This flaw could allow the attacker to read or manipulate data, or carry out further actions depending on the exposed API.
Affected Systems
The flaw affects Forget-C's Jellyfish AI Short Drama Studio in versions 0.1.0‑alpha through 0.3.2, i.e., 0.1.0‑alpha, 0.2.0, 0.3.0, 0.3.1, and 0.3.2. Users running any of these releases are potentially exposed unless authentication is piloted by external measures.
Risk and Exploitability
The CVSS score for this issue is 6.9, which places it in the “Medium” severity range, and the EPSS score is less than 1%, indicating a low anticipated exploitation probability. The vulnerability is not listed in the CISA KEV catalog. However, exploitability is high from a remote standpoint, with attackers able to trigger the harmful behavior over the network, assuming the vulnerable API is exposed. The confusion around missing authentication is a classic authentication–authorization weakness (CWE‑287, CWE‑306). Combining the moderate CVSS with a low EPSS still warrants timely remediation due to the potential for unauthorized data and system manipulation.
OpenCVE Enrichment