IDOR and Mass Assignment Vulnerability in Chyrp Lite Blogging Engine
CVE-2026-35173
6.5MEDIUM
What is CVE-2026-35173?
Chyrp Lite, a lightweight blogging engine, is susceptible to an IDOR (Insecure Direct Object Reference) and mass assignment issue. Prior to version 2026.01, this vulnerability allows authenticated users with editing permissions to modify posts that they do not own. By manipulating internal class properties within the post_attributes payload, an attacker can perform unauthorized actions on another user's posts, leading to potential post ownership takeovers. This significant security flaw has been addressed in version 2026.01, ensuring users have proper access controls.
Affected Version(s)
chyrp-lite < 2026.01
