VYPR

Automad

by Marcantondahmen

Source repositories

CVEs (1)

  • CVE-2026-45332higMay 27, 2026
    risk 0.45cvss epss

    ### Summary A Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The `/_api/user-collection/create-first-user` setup endpoint remains publicly accessible once…