PT-2025-43409 · Booklore · Booklore

Published

2025-10-22

·

Updated

2025-10-23

·

CVE-2025-62614

CVSS v4.0
8.7
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions BookLore versions 1.8.1 and prior
Description BookLore is a self-hosted web app for managing book collections. Versions prior to a recent update have an authentication bypass issue in the
BookMediaController
. This allows unauthenticated users to access and download book covers, thumbnails, and complete PDF/CBZ page content without authorization. The issue stems from missing access control annotations on multiple media endpoints and the
CoverJwtFilter
continuing request processing even without an authentication token. This enables attackers to enumerate and exfiltrate book content, bypassing download permissions. The issue was addressed with commit b226c43.
Recommendations Update BookLore to a version later than 1.8.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-62614
GHSA-363G-FHCQ-HVQP

Affected Products

Booklore