A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation o…
Low CVSS 3.7
Summary
A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been made public and could be used. The project was informed of the problem early through …
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/waooAI/waoowaoo/
- https://github.com/waooAI/waoowaoo/issues/201
- https://vuldb.com/cve/CVE-2026-15594
- https://vuldb.com/submit/855264
- https://vuldb.com/vuln/378109
- https://vuldb.com/vuln/378109/cti
- https://vuldb.com/submit/855264
Timeline
- nvd_ingest NVD