Open-Source Web Application Vulnerability in Chartbrew Exposes Sensitive Data
CVE-2026-40595
7.5HIGH
What is CVE-2026-40595?
The vulnerability in Chartbrew, an open-source web application, allows unauthenticated attackers to access and export sensitive chart data from public projects. This flaw arises from inadequate verification of whether a chart should be publicly accessible. Specifically, while project-level public access is checked, individual charts are not, enabling attackers who know the chart identifiers to compromise sensitive data that should remain hidden. The issue was rectified in version 5.0.0 of the application.
Affected Version(s)
chartbrew = 4.9.0
