PT-2026-22213 · Manyfold · Manyfold

Floppy

·

Publicado

2026-02-26

·

Atualizado

2026-02-27

·

CVE-2026-28225

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Manyfold versions prior to 0.133.1
Description Manyfold is a self-hosted web application for managing 3d models. A flaw exists in the get model method within the ModelFilesController (lines 158-160) where models are loaded using Model.find param(params[:model id]) without proper authorization checks via policy scope(). This bypasses Pundit authorization, potentially allowing unauthorized access to models. Other controllers correctly implement authorization using policy scope(Model).find param(). The model id parameter is involved in this issue.
Recommendations Update to version 0.133.1 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28225
GHSA-V8PW-3R2F-3FQM

Produtos afetados

Manyfold