Impact
Grimmory Tools' Download Endpoint, specifically the streamFileToResponse method in KoboController.java, has a flaw that allows an attacker to manipulate the bookId parameter. This manipulation bypasses the intended authorization checks, enabling the remote attacker to request and receive any file that the application can access. The weakness corresponds to CWE-285 and CWE-639. Because the vulnerability is triggered via standard HTTP requests, based on the description it is inferred that the attacker does not require any special credentials or local privileges, resulting in unauthorized data exposure.
Affected Systems
Vulnerable releases include grimmory-tools Grimmory versions up to 3.3.3 and 3.4.1. These versions are hosted under the Grimmory Tools project on GitHub and are commonly used in environments that expose the KoboController download functionality. No higher‑version fix has been documented in the public record, so all instances of the mentioned releases remain at risk unless addressed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, but the lack of an EPSS rating combined with an active public exploit increases the practical risk. Because the attack vector is remote and the vulnerability can be triggered through normal web traffic, it is feasible for an attacker who does not require prior authentication to compromise the confidentiality of stored files; based on the description it is inferred that the attacker does not need genuine credentials. The issue is not listed in the CISA KEV catalog, yet the public availability of the exploit suggests a higher likelihood of real‑world attacks than the raw score implies.
OpenCVE Enrichment