CVE-2026-39354

Source
https://cve.org/CVERecord?id=CVE-2026-39354
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39354.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-39354
Aliases
  • GHSA-768r-cv9p-wrcm
Published
2026-04-07T18:54:36.133Z
Modified
2026-07-15T01:49:17.191679367Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Scoold has an Authenticated Arbitrary Question Overwrite via Client-Controlled postId in POST /questions/ask
Details

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-privilege user to overwrite another user's existing question by supplying that question's public ID as the postId parameter to POST /questions/ask. Because question IDs are exposed in normal question URLs, a low-privilege attacker can take a victim question ID from a public page and cause attacker-controlled content to be stored under that existing question object. This causes direct integrity loss of user-generated content and corrupts the integrity of the existing discussion thread. This vulnerability is fixed in 1.66.2.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39354.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/erudika/scoold

Affected ranges

Type
GIT
Repo
https://github.com/erudika/scoold
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:erudika:scoold:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.66.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

1.*
1.24.1
1.24.10
1.24.11
1.24.2
1.24.3
1.24.4
1.24.5
1.24.6
1.24.7
1.24.8
1.24.9
1.25.0
1.25.1
1.25.2
1.25.3
1.25.4
1.25.5
1.26.0
1.26.1
1.28.0
1.28.1
1.28.10
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.28.8
1.28.9
1.29.0
1.29.1
1.29.2
1.29.3
1.29.4
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.31.0
1.31.1
1.31.2
1.31.3
1.31.4
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.39.4
1.40.0
1.40.1
1.40.2
1.40.3
1.40.4
1.40.5
1.41.0
1.41.1
1.41.2
1.42.1
1.43.0
1.43.1
1.43.2
1.43.3
1.44.0
1.45.0
1.46.0
1.46.1
1.46.2
1.46.3
1.48.0
1.48.1
1.48.2
1.49.0
1.49.1
1.49.2
1.49.3
1.49.4
1.49.5
1.49.6
1.49.7
1.50.0
1.50.1
1.50.2
1.50.3
1.50.4
1.50.5
1.51.0
1.51.1
1.51.2
1.51.3
1.52.0
1.52.1
1.52.2
1.52.3
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.56.1
1.57.0
1.57.1
1.57.2
1.57.3
1.57.4
1.57.5
1.58.0
1.58.1
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.64.2
1.64.3
1.64.4
1.64.5
1.65.0
1.66.0
1.66.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39354.json"