All CosmicBytez Labs articles tagged #API Security, across news, security advisories, how-to guides, and projects.
A breach at South Korea's government-backed startup platform leaked encrypted personal data after an encryption key was embedded directly in an API response.
docker-socket-proxy's CONTAINERS guard bypassed via GET requests to /archive, /export, /logs, and /top, exposing arbitrary file reads.
SiYuan's CheckAuth() middleware has no rate limiting, allowing unauthenticated attackers to brute-force API tokens and gain full admin access (CVSS 9.8).
SiYuan before v3.7.4 allows stored XSS via unescaped table column width values in style attributes. CVSS 9.0 Critical. Patch to v3.7.4.
SiYuan before v3.7.4 has no brute-force protection on its /api/* auth middleware, exposing the workspace to credential stuffing. CVSS 9.8.
Grav API plugin before 1.0.13 fails to enforce API key scope caps on the disable2fa endpoint, enabling privilege escalation.
Grav API plugin before 1.0.13 lets low-privilege API keys enable Twig processing on pages via a broken scope gate in PagesController.
A critical CVSS 9.9 flaw in the MaaS API allows any pod within a Kubernetes cluster to bypass the Kuadrant AuthPolicy gateway by forging X-MaaS-Username and X-MaaS-Group headers, enabling full privilege escalation without authentication.
A critical authorization bypass in nebula-mesh, the self-hosted control plane for Slack's Nebula VPN, allows any holder of a non-admin operator API key to...
The Grav CMS API plugin before version 1.0.8 fails to properly authorize API key generation and revocation, allowing low-privilege users to generate admin...
A critical authentication bypass in Kopia, a cross-platform backup tool for Windows, macOS, and Linux, allows unauthenticated access to repository API...
A critical CVSS 9.1 vulnerability in Crawl4AI before 0.8.7 allows attackers to write arbitrary files anywhere on the host filesystem via the Docker API's...
A critical authentication bypass in Flowise allows unauthenticated attackers to register accounts via an unprotected API endpoint and gain full platform...
A critical missing authorization vulnerability (CVSS 9.1) in Red Hat's migration-planner allows any authenticated user to send a DELETE request to...
A critical improper authentication vulnerability (CVSS 9.6) in Red Hat's migration-planner agent-API middleware allows authenticated agents to update...
A critical CVSS 9.8 vulnerability in M3WebServer hard-codes backend API keys in the production build. Attackers intercept them through verbose error handling…
A critical insecure direct object reference vulnerability allows authenticated users to pivot to any other user's profile by modifying an id parameter in...
A critical unauthenticated information disclosure vulnerability in the Gardyn smart garden platform exposes all registered user account information via a...
A CVSS 10.0 critical vulnerability in steam-trader 2.1.1 exposes Steam account credentials, identity secrets, and shared secrets to unauthenticated remote...
A critical unauthenticated information disclosure vulnerability in SiYuan, the personal knowledge management system, allows remote attackers to retrieve...
A critical path traversal vulnerability in SiYuan's /api/file/readDir interface allows unauthenticated remote attackers to traverse notebook directories...