PT-2026-35460 · Wooey · Wooey
Anch0R
·
Published
2026-04-27
·
Updated
2026-04-27
·
CVE-2026-7142
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Wooey versions prior to 0.13.3rc1
Description
An issue in the API Endpoint component allows for improper authorization via remote manipulation. The flaw exists within the
add or update script() function located in the wooey/api/scripts.py file.Recommendations
Upgrade to version 0.13.3rc1 or 0.14.0.
As a temporary workaround, restrict access to the
add or update script() function until the update is applied.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wooey