Impact
The vulnerability lies in the API route component of Vane, where authentication is omitted from a critical route. An attacker can exploit this flaw remotely, though the attack requires a high level of expertise and is considered difficult to execute. Successfully bypassing authentication grants the attacker unauthorized access to the API, which could lead to data exposure or further compromise of the system depending on the permissions granted to the route.
Affected Systems
The software affected is Vane by ItzCrazyKns, with all releases up to version 1.12.1 vulnerable. The missing authentication check resides in the route.ts file of the component API, and users of any of the released versions within that range are impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium‑to‑high severity, while the EPSS score is not available, so precise exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The attack vector is inferred to be remote, as the description states the attack may be initiated remotely, and the high complexity and difficulty imply that a dedicated attacker would be required to find and use a working exploit.
OpenCVE Enrichment