Missing Authentication in Forget-C Jellyfish AI Short Drama Studio by Forget-C
CVE-2026-93559

6.9MEDIUM

Key Information:

Vendor

Forget-c

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93559?

A vulnerability exists in Forget-C Jellyfish AI Short Drama Studio versions 0.1.0-alpha through 0.3.2, where an unknown function in the FastAPI component's backend/app/dependencies.py file allows for remote exploitation due to missing authentication. This flaw could permit unauthorized access and manipulation of the application's data or services. The related GitHub issue has remained inactive, indicating potential risks for users of these versions.

Affected Version(s)

Jellyfish AI Short Drama Studio 0.1.0-alpha

Jellyfish AI Short Drama Studio 0.2.0

Jellyfish AI Short Drama Studio 0.3.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

summmm (VulDB User)
VulDB CNA Team
.