Unrated severityOSV Advisory· Published Jan 19, 2026· Updated Jan 20, 2026
Whisper Money has IDOR Vulnerability on sync/balances endpoint
CVE-2026-23844
Description
Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulnerability. A user can update/create account balances in other users' bank accounts. Version 0.1.5 fixes the issue.
Affected products
1- Range: v0.1.1, v0.1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/whisper-money/whisper-money/commit/80117c3edeaf5c5a5166f3815fc555a15b5ce686mitrex_refsource_MISC
- github.com/whisper-money/whisper-money/pull/60mitrex_refsource_MISC
- github.com/whisper-money/whisper-money/security/advisories/GHSA-c4g3-wpxr-2m74mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.