← Back to CVE search

CVE-2026-5022

Unknown

Description

The -/api/v1/files/images/{flow_id}/{file_name}- endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.

CVSS 6.3EPSS 0.20400000000000001%Risk 0.64
View source
Published
2026-03-27 15:17:04
Affected versions
unknown
Type
Other
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X