GHSA-v4gp-hf5j-4566

Suggest an improvement
Source
https://github.com/advisories/GHSA-v4gp-hf5j-4566
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-v4gp-hf5j-4566/GHSA-v4gp-hf5j-4566.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v4gp-hf5j-4566
Aliases
  • CVE-2025-67796
Published
2026-05-04T21:30:25Z
Modified
2026-05-08T19:04:08.750408Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
Details

IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6.

Database specific
{
    "github_reviewed_at": "2026-05-08T18:52:25Z",
    "github_reviewed": true,
    "severity": "HIGH",
    "nvd_published_at": "2026-05-04T20:16:16Z",
    "cwe_ids": [
        "CWE-284"
    ]
}
References

Affected packages

PyPI / rdiffweb

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.6

Affected versions

0.*
0.9.2.dev1
0.9.3
0.9.4
0.9.5
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
1.*
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1b1
1.3.1b2
1.3.1
1.3.2
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.0
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.*
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.0
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10
2.4.11a1
2.4.11
2.5.0a7
2.5.0a8
2.5.0a9
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4b1
2.5.4
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.0
2.6.1
2.7.0a1
2.7.0a2
2.7.0a3
2.7.0
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2a1
2.8.2
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
2.10.3b1
2.10.4b1
2.10.4b2
2.10.4
2.10.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-v4gp-hf5j-4566/GHSA-v4gp-hf5j-4566.json"