VYPR

crawlab

by Crawlab Team

CVEs (1)

  • CVE-2026-75103HigAug 17, 2026
    risk 0.57cvss 8.8epss

    Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve…