VYPR

Dashboard

by Qt

CVEs (1)

  • CVE-2026-12593HigJul 9, 2026
    risk 0.00cvss epss 0.00

    The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. Precondition for successful exploitation…