Insecure Direct Object Reference in BookWyrm by BookWyrm Social
CVE-2026-86111
7.1HIGH
What is CVE-2026-86111?
The version 0.9.1 of BookWyrm fails to properly validate user visibility permissions when handling the status edit endpoint. Authenticated users can exploit this flaw to access and read private reviews, typically restricted to followers or direct recipients, by simply sequencing through status IDs. This oversight enables attackers to retrieve sensitive content that bypasses intended privacy measures, exposing followers-only and direct-message reviews through the edit interface.
Affected Version(s)
bookwyrm 0 <= 0.9.1
