VYPR

Server

by Spacebarchat

Source repositories

CVEs (3)

  • CVE-2026-70617HigAug 5, 2026
    risk 0.46cvss 8.1epss 0.00

    Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can…

  • CVE-2026-69114MedAug 10, 2026
    risk 0.35cvss 6.5epss

    Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel. Authenticated users with MANAGE_MESSAGES permission in any controlled…

  • CVE-2026-70618MedAug 5, 2026
    risk 0.21cvss 4.3epss 0.00

    Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification.…