IDOR and Mass Assignment Vulnerability in Chyrp Lite Blogging Engine
CVE-2026-35173

6.5MEDIUM

Key Information:

Vendor
CVE Published:
6 April 2026

What is CVE-2026-35173?

Chyrp Lite, a lightweight blogging engine, is susceptible to an IDOR (Insecure Direct Object Reference) and mass assignment issue. Prior to version 2026.01, this vulnerability allows authenticated users with editing permissions to modify posts that they do not own. By manipulating internal class properties within the post_attributes payload, an attacker can perform unauthorized actions on another user's posts, leading to potential post ownership takeovers. This significant security flaw has been addressed in version 2026.01, ensuring users have proper access controls.

Affected Version(s)

chyrp-lite < 2026.01

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.