VYPR

Growi

by Growilabs

Source repositories

CVEs (3)

  • CVE-2026-84205MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same page. Authenticated attackers can pair a…

  • CVE-2026-84204MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.

  • CVE-2026-80191Aug 25, 2026
    risk 0.00cvss —epss 0.00

    GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to be non-null, so a…