Medium severityNVD Advisory· Published Jul 7, 2026· Updated Jul 10, 2026
CVE-2026-55417
CVE-2026-55417
Description
Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile option, visiting their profile HTML route (/username) correctly returns 404. However, the /json AJAX listing endpoint does not apply the same check. An unauthenticated caller who knows the target's user ID can retrieve all of that user's publicly-scoped images, revealing the username (which should be private). This is patched in Chevereto v4.5.4. No known workarounds are available.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.