{"id":"CVE-2019-14537","aliases":["GHSA-vf23-f26f-mjj9"],"url":"https://o3.security/vulnerability/CVE-2019-14537","summary":"Access of Resource Using Incompatible Type ('Type Confusion')  in yourls/yourls","details":"### Impact\nYOURLS through 1.7.3 is affected by a type juggling vulnerability in the API component that can result in login bypass.\n\n### Patches\nhttps://github.com/YOURLS/YOURLS/releases/tag/1.7.4\nhttps://github.com/YOURLS/YOURLS/pull/2542\n\n### References\n* https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14537\n* https://github.com/Wocanilo/CVE-2019-14537\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [YOURLS repository](https://github.com/YOURLS/YOURLS)","published":"2019-08-07T17:15:12.337Z","modified":"2026-07-08T17:17:35.991750Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.05042,"percentile":0.91685,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"Packagist","name":"yourls/yourls","fixedVersion":"1.7.4"}],"fix":{"url":"https://github.com/YOURLS/YOURLS/pull/2542","label":"YOURLS/YOURLS#2542"},"references":[{"type":"ADVISORY","url":"https://github.com/YOURLS/YOURLS/releases"},{"type":"FIX","url":"https://github.com/YOURLS/YOURLS/commits/master"},{"type":"FIX","url":"https://github.com/YOURLS/YOURLS/pull/2542"},{"type":"EVIDENCE","url":"https://github.com/Wocanilo/CVE-2019-14537"},{"type":"EVIDENCE","url":"https://security-garage.com/index.php/cves/cve-2019-14537-api-authentication-bypass-via-type-juggling"},{"type":"WEB","url":"https://github.com/YOURLS/YOURLS/security/advisories/GHSA-vf23-f26f-mjj9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14537"},{"type":"PACKAGE","url":"https://github.com/YOURLS/YOURLS"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vf23-f26f-mjj9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T17:17:35.991750Z"}}